Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-3222-6w4v-43ww

около 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xxx-v399-cp66

около 4 лет назад

usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.

EPSS: Низкий
github логотип

GHSA-2xxx-mh72-rq2w

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.

EPSS: Низкий
github логотип

GHSA-2xxx-fhc8-9qvq

больше 4 лет назад

Ecto missing `is_nil` requirement

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xxw-xpx9-m6gm

около 4 лет назад

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

EPSS: Низкий
github логотип

GHSA-2xxw-6qjm-9qhq

около 4 лет назад

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2xxv-v658-gjc8

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.

EPSS: Низкий
github логотип

GHSA-2xxv-635v-2vww

больше 4 лет назад

Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL and DBMS_SQL.

EPSS: Низкий
github логотип

GHSA-2xxr-prx9-m533

около 2 лет назад

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xxq-pq3h-297f

6 месяцев назад

A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. Performing a manipulation of the argument apcliSsid results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xxq-g4wg-w8hr

около 4 лет назад

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0302.

EPSS: Средний
github логотип

GHSA-2xxp-mhvm-26p5

около 2 лет назад

A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2xxp-jv88-pg4x

больше 1 года назад

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2xxp-g6g6-xch7

4 месяца назад

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xxp-9232-mwj8

около 4 лет назад

duplicity 0.6.24 has improper verification of SSL certificates

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xxp-777x-hr57

около 2 лет назад

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2xxp-627h-jh7j

около 4 лет назад

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

EPSS: Низкий
github логотип

GHSA-2xxm-h632-fmch

около 4 лет назад

Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue in XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

EPSS: Низкий
github логотип

GHSA-2xxm-5jwx-7jmj

около 4 лет назад

The mintToken function of a smart contract implementation for YiTongCoin (YTC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xxm-3j3x-786w

больше 4 лет назад

Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3222-6w4v-43ww

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-2xxx-v399-cp66

usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxx-mh72-rq2w

Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2xxx-fhc8-9qvq

Ecto missing `is_nil` requirement

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2xxw-xpx9-m6gm

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxw-6qjm-9qhq

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

CVSS3: 7.2
5%
Низкий
около 4 лет назад
github логотип
GHSA-2xxv-v658-gjc8

Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2xxv-635v-2vww

Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL and DBMS_SQL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2xxr-prx9-m533

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2xxq-pq3h-297f

A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. Performing a manipulation of the argument apcliSsid results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-2xxq-g4wg-w8hr

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0302.

21%
Средний
около 4 лет назад
github логотип
GHSA-2xxp-mhvm-26p5

A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-2xxp-jv88-pg4x

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xxp-g6g6-xch7

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-2xxp-9232-mwj8

duplicity 0.6.24 has improper verification of SSL certificates

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxp-777x-hr57

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-2xxp-627h-jh7j

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2xxm-h632-fmch

Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue in XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

0%
Низкий
около 4 лет назад
github логотип
GHSA-2xxm-5jwx-7jmj

The mintToken function of a smart contract implementation for YiTongCoin (YTC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxm-3j3x-786w

Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу