Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-34wf-crw6-8386

3 месяца назад

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34wf-7h8g-xjhv

почти 2 года назад

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34wf-3773-f66q

12 месяцев назад

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34wc-vx7r-829j

4 месяца назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34wc-p67w-xmgr

больше 4 лет назад

The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.

EPSS: Низкий
github логотип

GHSA-34wc-m69q-wgr7

больше 4 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34wc-9m9j-23pc

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, crypto_authenc_esn_decrypt() can advance past the end of the destination scatterlist and trigger a NULL pointer dereference in scatterwalk_map_and_copy(), leading to a kernel panic (DoS). Add a minimum AAD length check to fail fast on invalid inputs.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34w9-p2mc-gqxq

больше 4 лет назад

Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.

EPSS: Низкий
github логотип

GHSA-34w9-hwjp-7h9h

больше 4 лет назад

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.

EPSS: Низкий
github логотип

GHSA-34w9-6vpg-vp3g

больше 2 лет назад

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-34w9-337w-mx68

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartiolabs Smart Notification allows Reflected XSS. This issue affects Smart Notification: from n/a through 10.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34w8-mcwr-vg29

около 1 года назад

CodeceptJS's incomprehensive sanitation can lead to Command Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34w8-jp4p-57mj

больше 4 лет назад

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34w6-68wc-gx7h

больше 4 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34w6-4rx6-2cg7

больше 4 лет назад

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195035.

EPSS: Низкий
github логотип

GHSA-34w5-cvqh-fxgw

больше 1 года назад

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-34w5-c283-j9fg

3 месяца назад

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

EPSS: Низкий
github логотип

GHSA-34w5-49cc-qp8r

больше 3 лет назад

The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-34w4-wrqp-j47g

почти 3 года назад

Sensitive cookie in HTTPS session without 'Secure' attribute in thorsten/phpmyfaq

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34w4-v7w4-hxvc

больше 4 лет назад

SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34wf-crw6-8386

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-34wf-7h8g-xjhv

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-34wf-3773-f66q

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-34wc-vx7r-829j

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-34wc-p67w-xmgr

The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-34wc-m69q-wgr7

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wc-9m9j-23pc

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, crypto_authenc_esn_decrypt() can advance past the end of the destination scatterlist and trigger a NULL pointer dereference in scatterwalk_map_and_copy(), leading to a kernel panic (DoS). Add a minimum AAD length check to fail fast on invalid inputs.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-34w9-p2mc-gqxq

Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34w9-hwjp-7h9h

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34w9-6vpg-vp3g

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34w9-337w-mx68

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartiolabs Smart Notification allows Reflected XSS. This issue affects Smart Notification: from n/a through 10.3.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-34w8-mcwr-vg29

CodeceptJS's incomprehensive sanitation can lead to Command Injection

CVSS3: 9.8
2%
Низкий
около 1 года назад
github логотип
GHSA-34w8-jp4p-57mj

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-34w6-68wc-gx7h

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34w6-4rx6-2cg7

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195035.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-34w5-cvqh-fxgw

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-34w5-c283-j9fg

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

0%
Низкий
3 месяца назад
github логотип
GHSA-34w5-49cc-qp8r

The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34w4-wrqp-j47g

Sensitive cookie in HTTPS session without 'Secure' attribute in thorsten/phpmyfaq

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-34w4-v7w4-hxvc

SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу