Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mpc-f7w9-hpmw

9 месяцев назад

A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of the component Management Interface. The manipulation of the argument WizardConfigured leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mp9-g8xj-wfxh

около 4 лет назад

Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mp8-qvqm-3xwq

почти 8 лет назад

Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProvider

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mp7-rh6f-rm8h

больше 4 лет назад

Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php.

EPSS: Низкий
github логотип

GHSA-2mp7-r7rc-5fh6

больше 4 лет назад

Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.

EPSS: Низкий
github логотип

GHSA-2mp7-hxhq-256h

больше 4 лет назад

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32174590. References: B-RB#107142.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2mp7-7vgg-f35r

5 месяцев назад

A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2mp7-775v-6hf6

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mp6-9mjc-p6jg

почти 4 года назад

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mp6-6cqc-j393

больше 4 лет назад

Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.

EPSS: Средний
github логотип

GHSA-2mp5-w5jx-qmrm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.

EPSS: Низкий
github логотип

GHSA-2mp5-q6v7-w9ff

больше 4 лет назад

Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.

EPSS: Низкий
github логотип

GHSA-2mp5-m968-gwr2

около 7 лет назад

Path Traversal in http-file-server

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mp5-jmvp-3q28

больше 1 года назад

Missing Authorization vulnerability in pupunzi mb.YTPlayer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects mb.YTPlayer: from n/a through 3.3.8.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mp5-6f9w-875v

больше 4 лет назад

Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2mp4-qw33-xj6q

больше 4 лет назад

A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.10; v3.6 versions prior to 3.6.13.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mp4-3r7m-mmg9

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.

EPSS: Низкий
github логотип

GHSA-2mp3-mchr-79rx

больше 4 лет назад

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mp2-jw3g-m6fw

4 месяца назад

Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2mp2-fxxh-hv2j

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() Add the missing put_disk() on the error path in blkcg_maybe_throttle_current(). When blkcg lookup, blkg lookup, or blkg_tryget() fails, the function jumps to the out label which only calls rcu_read_unlock() but does not release the disk reference acquired by blkcg_schedule_throttle() via get_device(). Since current->throttle_disk is already set to NULL before the lookup, blkcg_exit() cannot release this reference either, causing the disk to never be freed. Restore the reference release that was present as blk_put_queue() in the original code but was inadvertently dropped during the conversion from request_queue to gendisk.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mpc-f7w9-hpmw

A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of the component Management Interface. The manipulation of the argument WizardConfigured leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
10%
Низкий
9 месяцев назад
github логотип
GHSA-2mp9-g8xj-wfxh

Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mp8-qvqm-3xwq

Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProvider

CVSS3: 7.5
3%
Низкий
почти 8 лет назад
github логотип
GHSA-2mp7-rh6f-rm8h

Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp7-r7rc-5fh6

Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp7-hxhq-256h

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32174590. References: B-RB#107142.

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp7-7vgg-f35r

A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVSS3: 2.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2mp7-775v-6hf6

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mp6-9mjc-p6jg

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-2mp6-6cqc-j393

Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.

21%
Средний
больше 4 лет назад
github логотип
GHSA-2mp5-w5jx-qmrm

Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp5-q6v7-w9ff

Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp5-m968-gwr2

Path Traversal in http-file-server

CVSS3: 5.3
2%
Низкий
около 7 лет назад
github логотип
GHSA-2mp5-jmvp-3q28

Missing Authorization vulnerability in pupunzi mb.YTPlayer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects mb.YTPlayer: from n/a through 3.3.8.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mp5-6f9w-875v

Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp4-qw33-xj6q

A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.10; v3.6 versions prior to 3.6.13.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp4-3r7m-mmg9

Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp3-mchr-79rx

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-2mp2-jw3g-m6fw

Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

CVSS3: 8.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2mp2-fxxh-hv2j

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() Add the missing put_disk() on the error path in blkcg_maybe_throttle_current(). When blkcg lookup, blkg lookup, or blkg_tryget() fails, the function jumps to the out label which only calls rcu_read_unlock() but does not release the disk reference acquired by blkcg_schedule_throttle() via get_device(). Since current->throttle_disk is already set to NULL before the lookup, blkcg_exit() cannot release this reference either, causing the disk to never be freed. Restore the reference release that was present as blk_put_queue() in the original code but was inadvertently dropped during the conversion from request_queue to gendisk.

CVSS3: 5.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу