Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2v34-3hgh-5vvx

почти 2 года назад

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection attacks, for example for generating new X.509 certificates, or setting the time zone. These OS command injection vulnerabilities in the script generatesslreq.pml can be exploited as a low-privileged authenticated user to execute commands in the context of the Linux user www-data via shell metacharacters in HTTP POST data (e.g., the city parameter). The OS command injection vulnerability in the script settimezone.pml or setdatetime.pml (e.g., via the year parameter) requires an administrative user for the C-MOR web interface. By also exploiting a privilege-escalation vulnerability, it is possible to execute commands on the C-MOR system with root privileges.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2v33-cf4x-5rqf

больше 4 лет назад

ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.

EPSS: Низкий
github логотип

GHSA-2v33-9pfj-w95c

около 4 лет назад

Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v33-63wj-5g4p

10 месяцев назад

A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208. The affected element is an unknown function of the file /log.php. Such manipulation of the argument cemail/password leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2v33-23h8-f74g

больше 2 лет назад

A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-262310 is the identifier assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2v2x-9xmf-m2f7

больше 4 лет назад

Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.

EPSS: Низкий
github логотип

GHSA-2v2w-x4hx-4vf7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2v2w-8v8c-wcm9

больше 1 года назад

Rancher UI has Stored Cross-site Scripting vulnerability

CVSS3: 8.9
EPSS: Низкий
github логотип

GHSA-2v2w-7r2w-3hff

больше 4 лет назад

Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2v2v-fx7r-f2fh

больше 4 лет назад

pimcore is vulnerable to Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2v2r-vm5q-9pwc

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

EPSS: Низкий
github логотип

GHSA-2v2r-8h68-5rpj

около 4 лет назад

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.

EPSS: Низкий
github логотип

GHSA-2v2m-m9xc-2hp5

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.

EPSS: Низкий
github логотип

GHSA-2v2m-jqm3-cq3x

больше 4 лет назад

An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.

EPSS: Низкий
github логотип

GHSA-2v2m-h8mc-wjvq

больше 1 года назад

Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v2m-fh3w-x32m

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

EPSS: Низкий
github логотип

GHSA-2v2m-7p9m-5v4v

около 4 лет назад

Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2v2m-677r-5j24

около 4 лет назад

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.

EPSS: Низкий
github логотип

GHSA-2v2m-4w84-733f

10 месяцев назад

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-2v2h-qr9f-cf9h

больше 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v34-3hgh-5vvx

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection attacks, for example for generating new X.509 certificates, or setting the time zone. These OS command injection vulnerabilities in the script generatesslreq.pml can be exploited as a low-privileged authenticated user to execute commands in the context of the Linux user www-data via shell metacharacters in HTTP POST data (e.g., the city parameter). The OS command injection vulnerability in the script settimezone.pml or setdatetime.pml (e.g., via the year parameter) requires an administrative user for the C-MOR web interface. By also exploiting a privilege-escalation vulnerability, it is possible to execute commands on the C-MOR system with root privileges.

CVSS3: 7.2
3%
Низкий
почти 2 года назад
github логотип
GHSA-2v33-cf4x-5rqf

ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2v33-9pfj-w95c

Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v33-63wj-5g4p

A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208. The affected element is an unknown function of the file /log.php. Such manipulation of the argument cemail/password leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2v33-23h8-f74g

A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-262310 is the identifier assigned to this vulnerability.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2v2x-9xmf-m2f7

Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2v2w-x4hx-4vf7

Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.

CVSS3: 5.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v2w-8v8c-wcm9

Rancher UI has Stored Cross-site Scripting vulnerability

CVSS3: 8.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-2v2w-7r2w-3hff

Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v2v-fx7r-f2fh

pimcore is vulnerable to Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2v2r-vm5q-9pwc

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2v2r-8h68-5rpj

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v2m-m9xc-2hp5

Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v2m-jqm3-cq3x

An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v2m-h8mc-wjvq

Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v2m-fh3w-x32m

Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v2m-7p9m-5v4v

Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v2m-677r-5j24

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v2m-4w84-733f

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 2.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-2v2h-qr9f-cf9h

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

больше 2 лет назад

Уязвимостей на страницу