Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-2652-4r69-fm9r

больше 4 лет назад

SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid.

EPSS: Низкий
github логотип

GHSA-264x-wjpr-7j93

больше 4 лет назад

The Jack'd - Gay Chat & Dating (aka mobi.jackd.android) application 1.9.0a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-264x-w2cv-phgq

7 месяцев назад

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-264x-4r27-x5m2

больше 4 лет назад

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-264w-xrr7-6qqg

больше 4 лет назад

RCE vulnerability in Jenkins OpenShift Pipeline Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-264w-p3vv-mx7p

почти 3 года назад

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-264w-h7gv-xm4m

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 22b925449c84faa9b7496abe4f8f5661cb5eb3bf. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216480.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-264w-gw9g-fhgj

почти 4 года назад

Cross-site Scripting in librenms/librenms

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-264v-wvvx-84j4

больше 4 лет назад

PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the top parameter. NOTE: when allow_url_fopen is disabled, directory traversal attacks are possible to include and execute arbitrary local files.

EPSS: Низкий
github логотип

GHSA-264v-m8fm-76jm

5 месяцев назад

nimiq-transaction: Panic via `HistoryTreeProof` length mismatch

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-264v-69hm-998m

около 2 лет назад

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-264r-qr34-jpph

больше 4 лет назад

flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-264r-p5m9-6v8c

около 2 лет назад

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-264q-mfc4-v57c

больше 4 лет назад

kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.

EPSS: Низкий
github логотип

GHSA-264q-f23m-4cfj

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-264q-ch9j-7v9c

больше 4 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. When parsing the slave_mac parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9650.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-264q-3fvj-9xhx

больше 4 лет назад

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.

EPSS: Средний
github логотип

GHSA-264p-99wq-f4j6

больше 2 лет назад

Ion Java StackOverflow vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-264m-mv26-f7f5

больше 4 лет назад

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-264m-hxmc-hwjf

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: fuse: fix io-uring list corruption for terminated non-committed requests When a request is terminated before it has been committed, the request is not removed from the queue's list. This leaves a dangling list entry that leads to list corruption and use-after-free issues. Remove the request from the queue's list for terminated non-committed requests.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2652-4r69-fm9r

SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-264x-wjpr-7j93

The Jack'd - Gay Chat & Dating (aka mobi.jackd.android) application 1.9.0a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-264x-w2cv-phgq

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVSS3: 4.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-264x-4r27-x5m2

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.

CVSS3: 9.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-264w-xrr7-6qqg

RCE vulnerability in Jenkins OpenShift Pipeline Plugin

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-264w-p3vv-mx7p

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 4.6
0%
Низкий
почти 3 года назад
github логотип
GHSA-264w-h7gv-xm4m

A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 22b925449c84faa9b7496abe4f8f5661cb5eb3bf. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216480.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-264w-gw9g-fhgj

Cross-site Scripting in librenms/librenms

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-264v-wvvx-84j4

PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the top parameter. NOTE: when allow_url_fopen is disabled, directory traversal attacks are possible to include and execute arbitrary local files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-264v-m8fm-76jm

nimiq-transaction: Panic via `HistoryTreeProof` length mismatch

CVSS3: 3.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-264v-69hm-998m

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-264r-qr34-jpph

flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-264r-p5m9-6v8c

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-264q-mfc4-v57c

kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-264q-f23m-4cfj

Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-264q-ch9j-7v9c

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. When parsing the slave_mac parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9650.

CVSS3: 8.8
41%
Средний
больше 4 лет назад
github логотип
GHSA-264q-3fvj-9xhx

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.

14%
Средний
больше 4 лет назад
github логотип
GHSA-264p-99wq-f4j6

Ion Java StackOverflow vulnerability

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-264m-mv26-f7f5

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

CVSS3: 9.8
16%
Средний
больше 4 лет назад
github логотип
GHSA-264m-hxmc-hwjf

In the Linux kernel, the following vulnerability has been resolved: fuse: fix io-uring list corruption for terminated non-committed requests When a request is terminated before it has been committed, the request is not removed from the queue's list. This leaves a dangling list entry that leads to list corruption and use-after-free issues. Remove the request from the queue's list for terminated non-committed requests.

CVSS3: 7.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу