Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-29mv-gccw-23pv

около 4 лет назад

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29mr-mxx6-f3f5

около 4 лет назад

SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

EPSS: Низкий
github логотип

GHSA-29mr-gr4c-vf9c

около 4 лет назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-29mr-2jgg-289p

около 4 лет назад

PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29mq-gwwx-vg5f

около 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-29mq-c452-8pvf

9 месяцев назад

Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an authenticated user to cause the MFserver process to crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29mq-6jwf-w4hx

около 4 лет назад

Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).

EPSS: Низкий
github логотип

GHSA-29mq-29c5-43rg

около 4 лет назад

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 before 8.7(1.4), 9.0 before 9.0(1.1), and 9.1 before 9.1(1.2) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCud16590.

EPSS: Низкий
github логотип

GHSA-29mp-vjf6-73c4

больше 4 лет назад

Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

EPSS: Низкий
github логотип

GHSA-29mp-2hx5-9mm4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

EPSS: Низкий
github логотип

GHSA-29mm-w894-gvhw

около 4 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an integer overflow vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29mm-6j7g-rc29

больше 1 года назад

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-29mj-gxqm-6x8c

больше 4 лет назад

ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.

EPSS: Низкий
github логотип

GHSA-29mh-w3r4-79cm

больше 3 лет назад

Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-29mh-jw46-2rf9

около 4 лет назад

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible to set the IP address and hostname of the instance to any value, which is then stored in /etc/hosts. An attacker can then point metadata.google.internal to an arbitrary IP address and impersonate the GCE metadata server which make it is possible to instruct the OS Login PAM module to grant administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "adm" user from the OS Login entry.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29mh-h3mm-7r6h

около 4 лет назад

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

EPSS: Средний
github логотип

GHSA-29mh-8gx9-q2h8

около 1 года назад

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-29mf-w486-v3vc

10 месяцев назад

Bagisto is vulnerable to XSS through Admin Panel's product creation path

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-29mf-g5hc-vfvc

больше 1 года назад

This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29mf-95fh-hwxf

4 месяца назад

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29mv-gccw-23pv

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.

CVSS3: 9.8
69%
Средний
около 4 лет назад
github логотип
GHSA-29mr-mxx6-f3f5

SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-29mr-gr4c-vf9c

Magento 2 Community Edition XSS Vulnerability

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-29mr-2jgg-289p

PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-29mq-gwwx-vg5f

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

4%
Низкий
около 4 лет назад
github логотип
GHSA-29mq-c452-8pvf

Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an authenticated user to cause the MFserver process to crash.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-29mq-6jwf-w4hx

Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).

7%
Низкий
около 4 лет назад
github логотип
GHSA-29mq-29c5-43rg

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 before 8.7(1.4), 9.0 before 9.0(1.1), and 9.1 before 9.1(1.2) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCud16590.

2%
Низкий
около 4 лет назад
github логотип
GHSA-29mp-vjf6-73c4

Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-29mp-2hx5-9mm4

Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-29mm-w894-gvhw

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an integer overflow vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-29mm-6j7g-rc29

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.

CVSS3: 4.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-29mj-gxqm-6x8c

ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-29mh-w3r4-79cm

Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29mh-jw46-2rf9

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible to set the IP address and hostname of the instance to any value, which is then stored in /etc/hosts. An attacker can then point metadata.google.internal to an arbitrary IP address and impersonate the GCE metadata server which make it is possible to instruct the OS Login PAM module to grant administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "adm" user from the OS Login entry.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-29mh-h3mm-7r6h

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

16%
Средний
около 4 лет назад
github логотип
GHSA-29mh-8gx9-q2h8

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.1
0%
Низкий
около 1 года назад
github логотип
GHSA-29mf-w486-v3vc

Bagisto is vulnerable to XSS through Admin Panel's product creation path

CVSS3: 8.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-29mf-g5hc-vfvc

This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-29mf-95fh-hwxf

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу