Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xmr6-rg25-v9gg

около 4 лет назад

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.

EPSS: Низкий
github логотип

GHSA-xmr6-p3jv-fvww

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

EPSS: Низкий
github логотип

GHSA-xmr6-mm5f-8mf2

6 месяцев назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xmr3-m6h9-383p

больше 4 лет назад

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.

EPSS: Низкий
github логотип

GHSA-xmr3-fcjj-mc3v

больше 4 лет назад

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

EPSS: Низкий
github логотип

GHSA-xmr2-xffw-xxmx

около 4 лет назад

iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmr2-cqqm-jr8m

около 4 лет назад

Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-xmr2-c47x-rm4p

больше 1 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Shared Resource Manipulation.This issue affects Mediawiki - Mobile Frontend Extension: from 1.39 through 1.43.

EPSS: Низкий
github логотип

GHSA-xmr2-77rg-h53j

около 4 лет назад

AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmqx-8fv3-jc9q

около 4 лет назад

A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to create a scheduled meeting template. A successful exploit could allow the attacker to create a scheduled meeting template that would belong to a user other than themselves.

EPSS: Низкий
github логотип

GHSA-xmqw-mq56-x22h

около 1 года назад

Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through 1.12. Affected action "woo_slide_pro_delete_slider".

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmqw-mh3q-89r9

около 4 лет назад

The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the _bz_callback character set.

EPSS: Низкий
github логотип

GHSA-xmqw-gc65-wj6q

около 4 лет назад

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new routes to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in passing commands to a "popen" API in the function and thus result in command injection on the device. If the firmware version AL-R096 is dissected using binwalk tool, we obtain a cpio-root archive which contains the filesystem set up on the device that contains all the binaries. The binary "goahead" is the one that has the vulnerable function that receives the values sent by the POST request. If we open this binary in IDA-pro we will notice that this follows a MIPS little endian format. The function sub_00420F38 in IDA pro is identified to be receiving the values sent in the POST request and the value set in POST parameter "dest" is extracted at address 0x00420FC4. The PO...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmqw-f73x-r3cq

почти 2 года назад

A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument curTime leads to buffer overflow. The exploit has been disclosed to the public and may be used.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmqw-3rv2-c2hm

больше 4 лет назад

IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 128372.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmqv-pfw7-qmj7

около 4 лет назад

Jenkins ElectricFlow Plugin globally and unconditionally disabled SSL/TLS certificate validation

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmqv-9j73-gq5h

около 4 лет назад

NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.

EPSS: Низкий
github логотип

GHSA-xmqr-m3g6-f3h7

больше 4 лет назад

Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmqq-mrv9-8jqp

больше 4 лет назад

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated user in order to exploit the vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmqp-wmrm-vqv8

почти 3 года назад

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell meta-characters in the PHPSESSID cookie.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmr6-rg25-v9gg

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmr6-p3jv-fvww

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmr6-mm5f-8mf2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

CVSS3: 4.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-xmr3-m6h9-383p

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xmr3-fcjj-mc3v

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmr2-xffw-xxmx

iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

CVSS3: 9.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-xmr2-cqqm-jr8m

Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xmr2-c47x-rm4p

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Shared Resource Manipulation.This issue affects Mediawiki - Mobile Frontend Extension: from 1.39 through 1.43.

0%
Низкий
больше 1 года назад
github логотип
GHSA-xmr2-77rg-h53j

AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xmqx-8fv3-jc9q

A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to create a scheduled meeting template. A successful exploit could allow the attacker to create a scheduled meeting template that would belong to a user other than themselves.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmqw-mq56-x22h

Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through 1.12. Affected action "woo_slide_pro_delete_slider".

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xmqw-mh3q-89r9

The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the _bz_callback character set.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmqw-gc65-wj6q

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new routes to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in passing commands to a "popen" API in the function and thus result in command injection on the device. If the firmware version AL-R096 is dissected using binwalk tool, we obtain a cpio-root archive which contains the filesystem set up on the device that contains all the binaries. The binary "goahead" is the one that has the vulnerable function that receives the values sent by the POST request. If we open this binary in IDA-pro we will notice that this follows a MIPS little endian format. The function sub_00420F38 in IDA pro is identified to be receiving the values sent in the POST request and the value set in POST parameter "dest" is extracted at address 0x00420FC4. The PO...

CVSS3: 8.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-xmqw-f73x-r3cq

A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument curTime leads to buffer overflow. The exploit has been disclosed to the public and may be used.

CVSS3: 5.5
3%
Низкий
почти 2 года назад
github логотип
GHSA-xmqw-3rv2-c2hm

IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 128372.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xmqv-pfw7-qmj7

Jenkins ElectricFlow Plugin globally and unconditionally disabled SSL/TLS certificate validation

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmqv-9j73-gq5h

NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xmqr-m3g6-f3h7

Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmqq-mrv9-8jqp

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated user in order to exploit the vulnerability.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmqp-wmrm-vqv8

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell meta-characters in the PHPSESSID cookie.

CVSS3: 9.8
66%
Средний
почти 3 года назад

Уязвимостей на страницу