Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3rx9-3f42-rqvh

больше 4 лет назад

Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving movement of a SCRIPT element across documents.

EPSS: Низкий
github логотип

GHSA-3rx8-r3v3-xqwp

больше 4 лет назад

PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

EPSS: Низкий
github логотип

GHSA-3rx8-q5x6-m56j

около 3 лет назад

A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][ampersand]method=sms of the component OTP URI Interface. The manipulation leads to information exposure through discrepancy. It is possible to initiate the attack remotely. The identifier VDB-233253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rx7-xcvr-j7v2

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.

EPSS: Средний
github логотип

GHSA-3rx7-fmcf-hpgr

около 2 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: before v3.5.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rx6-q2qg-r8cc

больше 4 лет назад

The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3rx6-5vvp-hhgq

больше 4 лет назад

A cross-site scripting (XSS) vulnerability in BoltWire v7.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3rx6-2g27-8gfq

около 1 месяца назад

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3rx5-gfw3-66w3

больше 4 лет назад

SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rx5-cvg5-f68h

4 месяца назад

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rx5-2rm5-fvhx

больше 4 лет назад

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3rx2-x6mx-grj3

почти 7 лет назад

Cross-site scripting in Apache JSPWiki

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3rwx-rphm-m3g7

больше 4 лет назад

In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173473906

EPSS: Низкий
github логотип

GHSA-3rwx-3vwh-mwxc

больше 4 лет назад

Jenkins Vulnerable to Denial of Service (DoS)

EPSS: Низкий
github логотип

GHSA-3rww-fm75-jc23

около 1 года назад

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3rww-7g94-g9qj

больше 4 лет назад

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rwv-jrrg-99x3

больше 2 лет назад

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rwv-g3jc-r7cc

больше 4 лет назад

An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c

EPSS: Низкий
github логотип

GHSA-3rwr-qrj8-m997

2 дня назад

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block attribute into an HTML class attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3rwr-mwr8-225x

4 месяца назад

Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name containing traversal sequences ../../wp-config.php to access sensitive configuration files.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rx9-3f42-rqvh

Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving movement of a SCRIPT element across documents.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rx8-r3v3-xqwp

PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rx8-q5x6-m56j

A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][ampersand]method=sms of the component OTP URI Interface. The manipulation leads to information exposure through discrepancy. It is possible to initiate the attack remotely. The identifier VDB-233253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-3rx7-xcvr-j7v2

Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.

64%
Средний
больше 4 лет назад
github логотип
GHSA-3rx7-fmcf-hpgr

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: before v3.5.0.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3rx6-q2qg-r8cc

The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rx6-5vvp-hhgq

A cross-site scripting (XSS) vulnerability in BoltWire v7.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rx6-2g27-8gfq

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3rx5-gfw3-66w3

SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rx5-cvg5-f68h

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3rx5-2rm5-fvhx

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

CVSS3: 9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rx2-x6mx-grj3

Cross-site scripting in Apache JSPWiki

CVSS3: 6.1
3%
Низкий
почти 7 лет назад
github логотип
GHSA-3rwx-rphm-m3g7

In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173473906

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwx-3vwh-mwxc

Jenkins Vulnerable to Denial of Service (DoS)

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rww-fm75-jc23

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3rww-7g94-g9qj

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwv-jrrg-99x3

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3rwv-g3jc-r7cc

An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwr-qrj8-m997

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block attribute into an HTML class attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
2 дня назад
github логотип
GHSA-3rwr-mwr8-225x

Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name containing traversal sequences ../../wp-config.php to access sensitive configuration files.

CVSS3: 7.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу