Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34gv-vxwq-v84r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.

EPSS: Низкий
github логотип

GHSA-34gv-g2q3-w3f7

больше 4 лет назад

Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.

EPSS: Низкий
github логотип

GHSA-34gv-fqgg-h594

около 4 лет назад

The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.

EPSS: Низкий
github логотип

GHSA-34gr-x89x-88vq

около 4 лет назад

The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of service (memory corruption) via unknown vectors.

EPSS: Низкий
github логотип

GHSA-34gr-jxh4-rxfv

больше 3 лет назад

Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may allow a remote attacker to execute an arbitrary code with SYSTEM privileges by sending a specially crafted script to the affected device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34gq-5vmf-jf2j

23 дня назад

Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34gq-5fpf-r3h5

около 4 лет назад

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setIpQosRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34gp-mhv2-cg2f

больше 4 лет назад

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34gp-fpcr-4fhh

около 4 лет назад

Unspecified vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to obtain sensitive information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-34gp-5c7w-p6jr

2 месяца назад

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-34gm-qfww-6gwm

больше 1 года назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34gm-7vmj-9jg6

11 месяцев назад

Hardcoded credentials in default configuration of PPress 0.0.9.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34gm-4qqx-g892

больше 4 лет назад

Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-34gj-4vw3-fwwm

около 4 лет назад

Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter.

EPSS: Низкий
github логотип

GHSA-34gh-3cwv-wvp2

около 6 лет назад

Directory traversal in rollup-plugin-server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34gh-2h52-xg3c

больше 4 лет назад

Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34gg-g64c-2h3q

около 4 лет назад

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34gf-pfjm-cq2w

около 3 лет назад

A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34gc-wf8f-4rcx

около 4 лет назад

Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

EPSS: Средний
github логотип

GHSA-34g8-f786-j67w

около 4 лет назад

CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34gv-vxwq-v84r

Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34gv-g2q3-w3f7

Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34gv-fqgg-h594

The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.

2%
Низкий
около 4 лет назад
github логотип
GHSA-34gr-x89x-88vq

The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of service (memory corruption) via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34gr-jxh4-rxfv

Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may allow a remote attacker to execute an arbitrary code with SYSTEM privileges by sending a specially crafted script to the affected device.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34gq-5vmf-jf2j

Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 6.3
0%
Низкий
23 дня назад
github логотип
GHSA-34gq-5fpf-r3h5

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setIpQosRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-34gp-mhv2-cg2f

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34gp-fpcr-4fhh

Unspecified vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to obtain sensitive information via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-34gp-5c7w-p6jr

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 2.4
0%
Низкий
2 месяца назад
github логотип
GHSA-34gm-qfww-6gwm

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-34gm-7vmj-9jg6

Hardcoded credentials in default configuration of PPress 0.0.9.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-34gm-4qqx-g892

Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment.

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34gj-4vw3-fwwm

Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34gh-3cwv-wvp2

Directory traversal in rollup-plugin-server

CVSS3: 7.5
2%
Низкий
около 6 лет назад
github логотип
GHSA-34gh-2h52-xg3c

Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-34gg-g64c-2h3q

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
4%
Низкий
около 4 лет назад
github логотип
GHSA-34gf-pfjm-cq2w

A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-34gc-wf8f-4rcx

Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

13%
Средний
около 4 лет назад
github логотип
GHSA-34g8-f786-j67w

CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.

CVSS3: 9.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу