Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 346 378

Количество 346 378

github логотип

GHSA-23v6-mxrm-p953

около 4 лет назад

Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files such as (1) save.dat and (2) apply.log, which can contain other credentials such as the Skype username and password.

EPSS: Низкий
github логотип

GHSA-23v6-h45q-rxch

3 месяца назад

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied values consumed from user-created content blocks. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-23v6-7r6w-c9x5

8 месяцев назад

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-23v6-5g43-4fhp

около 2 лет назад

D-Link DIR-X3260 SetSysEmailSettings AccountName Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within prog.cgi, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21159.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-23v6-32v8-5cg2

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Aviana aviana allows PHP Local File Inclusion.This issue affects Aviana: from n/a through <= 2.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23v5-vgf6-5452

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix missing SPDIFI1 index handling SPDIF1 DAIO type isn't properly handled in daio_device_index() for hw20k2, and it returned -EINVAL, which ended up with the out-of-bounds array access. Follow the hw20k1 pattern and return the proper index for this type, too.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23v5-hjqv-hwj8

около 4 лет назад

IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized user. IBM X-Force ID: 178182.

EPSS: Низкий
github логотип

GHSA-23v5-3rr6-rp4h

около 4 лет назад

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23v4-qfpm-c2cx

около 4 лет назад

The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or application images can be installed. Firmware updates for the Front End Processor (FEP) module are performed via access to the SSH interface (22/TCP), where a .hex file image is transferred and a bootloader script invoked. File system, kernel, package, and bundle updates are supplied as RPM (RPM Package Manager) files while FEP updates are supplied as S-rec files. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-23v4-p97p-cxrg

около 4 лет назад

The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23v4-8fh5-m694

около 4 лет назад

The Mitsubishi Road Assist (aka com.agero.mitsubishi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-23v4-4xf3-43mx

около 4 лет назад

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate CPP frame messages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28803645 and Qualcomm internal bug CR674712.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23v3-qfrj-wmgh

почти 8 лет назад

Moderate severity vulnerability that affects actionpack

EPSS: Низкий
github логотип

GHSA-23v2-r3m3-4j3v

почти 3 года назад

Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23v2-gv35-vww5

8 месяцев назад

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-23v2-6gx7-7pp6

3 месяца назад

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23rx-x963-qprq

около 4 лет назад

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

EPSS: Низкий
github логотип

GHSA-23rx-gwwc-2hq5

больше 4 лет назад

In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

EPSS: Низкий
github логотип

GHSA-23rx-f2xv-5pg9

около 4 лет назад

Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130

EPSS: Низкий
github логотип

GHSA-23rx-c3g5-hv9w

около 2 лет назад

Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23v6-mxrm-p953

Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files such as (1) save.dat and (2) apply.log, which can contain other credentials such as the Skype username and password.

3%
Низкий
около 4 лет назад
github логотип
GHSA-23v6-h45q-rxch

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied values consumed from user-created content blocks. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
3 месяца назад
github логотип
GHSA-23v6-7r6w-c9x5

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS3: 5.9
0%
Низкий
8 месяцев назад
github логотип
GHSA-23v6-5g43-4fhp

D-Link DIR-X3260 SetSysEmailSettings AccountName Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within prog.cgi, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21159.

CVSS3: 8
1%
Низкий
около 2 лет назад
github логотип
GHSA-23v6-32v8-5cg2

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Aviana aviana allows PHP Local File Inclusion.This issue affects Aviana: from n/a through <= 2.1.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
github логотип
GHSA-23v5-vgf6-5452

In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix missing SPDIFI1 index handling SPDIF1 DAIO type isn't properly handled in daio_device_index() for hw20k2, and it returned -EINVAL, which ended up with the out-of-bounds array access. Follow the hw20k1 pattern and return the proper index for this type, too.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-23v5-hjqv-hwj8

IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized user. IBM X-Force ID: 178182.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23v5-3rr6-rp4h

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-23v4-qfpm-c2cx

The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or application images can be installed. Firmware updates for the Front End Processor (FEP) module are performed via access to the SSH interface (22/TCP), where a .hex file image is transferred and a bootloader script invoked. File system, kernel, package, and bundle updates are supplied as RPM (RPM Package Manager) files while FEP updates are supplied as S-rec files. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 7.2
0%
Низкий
около 4 лет назад
github логотип
GHSA-23v4-p97p-cxrg

The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-23v4-8fh5-m694

The Mitsubishi Road Assist (aka com.agero.mitsubishi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-23v4-4xf3-43mx

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate CPP frame messages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28803645 and Qualcomm internal bug CR674712.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-23v3-qfrj-wmgh

Moderate severity vulnerability that affects actionpack

почти 8 лет назад
github логотип
GHSA-23v2-r3m3-4j3v

Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-23v2-gv35-vww5

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-23v2-6gx7-7pp6

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.

CVSS3: 5.3
1%
Низкий
3 месяца назад
github логотип
GHSA-23rx-x963-qprq

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23rx-gwwc-2hq5

In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23rx-f2xv-5pg9

Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130

1%
Низкий
около 4 лет назад
github логотип
GHSA-23rx-c3g5-hv9w

Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag

CVSS3: 8.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу