Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-37g4-qqqv-7m99

6 месяцев назад

Intake has a Command Injection via shell() Expansion in Parameter Defaults

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37g4-3496-g55p

6 месяцев назад

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-37g4-2454-w65h

больше 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho allows Path Traversal. This issue affects Litho: from n/a through 3.0.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-37g3-xgx7-448m

больше 4 лет назад

Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.

EPSS: Низкий
github логотип

GHSA-37g3-f8w7-7773

больше 4 лет назад

Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.

EPSS: Низкий
github логотип

GHSA-37g3-5cwf-286g

больше 4 лет назад

A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

EPSS: Средний
github логотип

GHSA-37g3-3m5c-7mjc

больше 2 лет назад

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37fx-p8jg-8c9r

больше 4 лет назад

The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.

EPSS: Низкий
github логотип

GHSA-37fx-4x77-f4qp

больше 4 лет назад

The Probe Builder Service (aka PBOVISServer.exe) in European Performance Systems (EPS) Probe Builder 2.2 before A.02.20.901, as used in HP OpenView Internet Services (OVIS) on Windows, allows remote attackers to kill arbitrary processes via a process ID number in an unspecified opcode.

EPSS: Низкий
github логотип

GHSA-37fx-2m8v-2x4j

около 3 лет назад

NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-37fw-xv85-q5fg

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER isotp_release() looked up the bound network device via dev_get_by_index() using the stored ifindex. During device unregistration the device is unlisted from the ifindex hash before the NETDEV_UNREGISTER notifier chain runs, so a concurrent isotp_release() could find no device, skip can_rx_unregister() entirely, and still proceed to free the socket. Since isotp_release() had already removed itself from the isotp notifier list at that point, isotp_notify() would never get a chance to clean up either, leaving a stale CAN filter that keeps pointing at the freed socket. Fix this the same way raw.c already does: hold a tracked reference to the bound net_device in the socket (so->dev/so->dev_tracker) from bind() onward instead of re-resolving it from the ifindex, and serialize bind()/release() with rtnl_lock() so that so->dev is always consistent with...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37fw-j45g-2rh2

около 2 лет назад

Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37fw-gh9c-pf7v

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37fv-cfw9-w5r9

4 месяца назад

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37fr-rv4j-c6g2

2 месяца назад

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37fq-hhvj-f3fr

больше 4 лет назад

Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37fq-47qj-6j5j

6 месяцев назад

YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter"

EPSS: Низкий
github логотип

GHSA-37fp-qc5g-vpxr

больше 4 лет назад

util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37fp-4fg2-x96g

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

EPSS: Низкий
github логотип

GHSA-37fm-chgp-6j58

больше 4 лет назад

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37g4-qqqv-7m99

Intake has a Command Injection via shell() Expansion in Parameter Defaults

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-37g4-3496-g55p

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-37g4-2454-w65h

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho allows Path Traversal. This issue affects Litho: from n/a through 3.0.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-37g3-xgx7-448m

Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37g3-f8w7-7773

Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37g3-5cwf-286g

A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

14%
Средний
больше 4 лет назад
github логотип
GHSA-37g3-3m5c-7mjc

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37fx-p8jg-8c9r

The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37fx-4x77-f4qp

The Probe Builder Service (aka PBOVISServer.exe) in European Performance Systems (EPS) Probe Builder 2.2 before A.02.20.901, as used in HP OpenView Internet Services (OVIS) on Windows, allows remote attackers to kill arbitrary processes via a process ID number in an unspecified opcode.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-37fx-2m8v-2x4j

NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 4
0%
Низкий
около 3 лет назад
github логотип
GHSA-37fw-xv85-q5fg

In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER isotp_release() looked up the bound network device via dev_get_by_index() using the stored ifindex. During device unregistration the device is unlisted from the ifindex hash before the NETDEV_UNREGISTER notifier chain runs, so a concurrent isotp_release() could find no device, skip can_rx_unregister() entirely, and still proceed to free the socket. Since isotp_release() had already removed itself from the isotp notifier list at that point, isotp_notify() would never get a chance to clean up either, leaving a stale CAN filter that keeps pointing at the freed socket. Fix this the same way raw.c already does: hold a tracked reference to the bound net_device in the socket (so->dev/so->dev_tracker) from bind() onward instead of re-resolving it from the ifindex, and serialize bind()/release() with rtnl_lock() so that so->dev is always consistent with...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-37fw-j45g-2rh2

Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-37fw-gh9c-pf7v

Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-37fv-cfw9-w5r9

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-37fr-rv4j-c6g2

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-37fq-hhvj-f3fr

Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37fq-47qj-6j5j

YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter"

0%
Низкий
6 месяцев назад
github логотип
GHSA-37fp-qc5g-vpxr

util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37fp-4fg2-x96g

Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37fm-chgp-6j58

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу