Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-3mmm-4r2q-pghm

больше 4 лет назад

Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-3mmm-4792-65w2

больше 4 лет назад

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

EPSS: Низкий
github логотип

GHSA-3mmj-vfm4-rpfq

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp.

EPSS: Низкий
github логотип

GHSA-3mmj-mrr2-5rmx

больше 4 лет назад

Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.

EPSS: Низкий
github логотип

GHSA-3mmj-45hw-28gw

больше 4 лет назад

Unspecified vulnerability in Oracle VM VirtualBox 3.0, 3.1, 3.2, and 4.0 through 4.0.8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Guest Additions for Windows.

EPSS: Низкий
github логотип

GHSA-3mmh-vq9w-4c3g

почти 4 года назад

Microweber vulnerable to Reflected Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mmh-p93r-vxvf

4 месяца назад

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mmh-h28h-wgxq

больше 4 лет назад

The “WooLentor – WooCommerce Elementor Addons + Builder� WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

EPSS: Низкий
github логотип

GHSA-3mmg-7c2q-8938

8 месяцев назад

`sha-rust` was removed from crates.io for malicious code

EPSS: Низкий
github логотип

GHSA-3mmf-7v44-cphp

больше 4 лет назад

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.

EPSS: Низкий
github логотип

GHSA-3mmf-6wp6-5hfj

больше 3 лет назад

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3mmf-29wp-jc9p

почти 2 года назад

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3mmc-w8vq-jvw8

больше 4 лет назад

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

EPSS: Низкий
github логотип

GHSA-3mm9-64xc-vf47

7 месяцев назад

A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3mm9-2p44-rw39

больше 2 лет назад

Silverstripe SiteTree Creation Permission Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm6-vwmh-qm9c

больше 4 лет назад

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mm6-mv5c-6hfv

больше 4 лет назад

LastPass prior to 2.5.1 has an insecure PIN implementation.

EPSS: Низкий
github логотип

GHSA-3mm6-hc5r-p5rx

больше 4 лет назад

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm6-4hpm-pgrc

больше 4 лет назад

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mm5-rh7g-ph5j

больше 4 лет назад

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mmm-4r2q-pghm

Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained from third party information.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3mmm-4792-65w2

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mmj-vfm4-rpfq

Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mmj-mrr2-5rmx

Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mmj-45hw-28gw

Unspecified vulnerability in Oracle VM VirtualBox 3.0, 3.1, 3.2, and 4.0 through 4.0.8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Guest Additions for Windows.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mmh-vq9w-4c3g

Microweber vulnerable to Reflected Cross-site Scripting

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-3mmh-p93r-vxvf

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3mmh-h28h-wgxq

The “WooLentor – WooCommerce Elementor Addons + Builder� WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mmg-7c2q-8938

`sha-rust` was removed from crates.io for malicious code

8 месяцев назад
github логотип
GHSA-3mmf-7v44-cphp

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mmf-6wp6-5hfj

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

CVSS3: 8.8
28%
Средний
больше 3 лет назад
github логотип
GHSA-3mmf-29wp-jc9p

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.

CVSS3: 4.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mmc-w8vq-jvw8

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm9-64xc-vf47

A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3mm9-2p44-rw39

Silverstripe SiteTree Creation Permission Vulnerability

CVSS3: 7.5
больше 2 лет назад
github логотип
GHSA-3mm6-vwmh-qm9c

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm6-mv5c-6hfv

LastPass prior to 2.5.1 has an insecure PIN implementation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm6-hc5r-p5rx

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm6-4hpm-pgrc

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm5-rh7g-ph5j

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу