Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 567

Количество 359 567

github логотип

GHSA-xgmr-hcvf-x3qc

6 дней назад

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xgmq-mgc9-gwfc

6 месяцев назад

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgmp-w3rr-9p7r

больше 4 лет назад

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

EPSS: Низкий
github логотип

GHSA-xgmp-rp9g-wppg

больше 4 лет назад

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

EPSS: Средний
github логотип

GHSA-xgmp-mj76-c47c

больше 4 лет назад

Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.

EPSS: Низкий
github логотип

GHSA-xgmm-vjx3-4m7q

около 4 лет назад

Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgmm-v76r-g7gj

около 4 лет назад

Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to access the protecting information, resulting in the elevation of the privilege.

EPSS: Низкий
github логотип

GHSA-xgmm-9xmm-8qv5

больше 1 года назад

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xgmm-8j9v-c9wx

2 месяца назад

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xgmm-3vvr-6c8j

почти 3 года назад

Index out of bounds leading to crash

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xgmj-r659-f4c7

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xgmj-j94q-46cv

6 месяцев назад

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgmj-8cq2-4f7j

больше 4 лет назад

The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.

EPSS: Низкий
github логотип

GHSA-xgmj-5fg9-4g8f

больше 1 года назад

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xgmh-rvpw-6498

больше 4 лет назад

Reflected cross-site-scripting vulnerability in report URL of Jenkins CppNCSS Plugin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgmh-gfxw-2hvv

около 4 лет назад

SaltStack Salt Server Side Template Injection

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xgmh-f6r2-39xq

больше 2 лет назад

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xgmh-4vh7-2fjj

больше 4 лет назад

GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgmg-hrgx-6gqq

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-dspi: Fix crash when not using GPIO chip select Add check for the return value of spi_get_csgpiod() to avoid passing a NULL pointer to gpiod_direction_output(), preventing a crash when GPIO chip select is not used. Fix below crash: [ 4.251960] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ 4.260762] Mem abort info: [ 4.263556] ESR = 0x0000000096000004 [ 4.267308] EC = 0x25: DABT (current EL), IL = 32 bits [ 4.272624] SET = 0, FnV = 0 [ 4.275681] EA = 0, S1PTW = 0 [ 4.278822] FSC = 0x04: level 0 translation fault [ 4.283704] Data abort info: [ 4.286583] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 4.292074] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 4.297130] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 4.302445] [0000000000000000] user address but active_mm is swapper [ 4.308805] Internal error: Oops: 0000...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xgmg-7q7c-fhxx

около 2 лет назад

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgmr-hcvf-x3qc

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user.

CVSS3: 6.6
1%
Низкий
6 дней назад
github логотип
GHSA-xgmq-mgc9-gwfc

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xgmp-w3rr-9p7r

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmp-rp9g-wppg

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

13%
Средний
больше 4 лет назад
github логотип
GHSA-xgmp-mj76-c47c

Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmm-vjx3-4m7q

Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xgmm-v76r-g7gj

Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to access the protecting information, resulting in the elevation of the privilege.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xgmm-9xmm-8qv5

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xgmm-8j9v-c9wx

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

CVSS3: 7.4
0%
Низкий
2 месяца назад
github логотип
GHSA-xgmm-3vvr-6c8j

Index out of bounds leading to crash

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xgmj-r659-f4c7

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xgmj-j94q-46cv

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xgmj-8cq2-4f7j

The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmj-5fg9-4g8f

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgmh-rvpw-6498

Reflected cross-site-scripting vulnerability in report URL of Jenkins CppNCSS Plugin

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmh-gfxw-2hvv

SaltStack Salt Server Side Template Injection

CVSS3: 9.8
11%
Средний
около 4 лет назад
github логотип
GHSA-xgmh-f6r2-39xq

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgmh-4vh7-2fjj

GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmg-hrgx-6gqq

In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-dspi: Fix crash when not using GPIO chip select Add check for the return value of spi_get_csgpiod() to avoid passing a NULL pointer to gpiod_direction_output(), preventing a crash when GPIO chip select is not used. Fix below crash: [ 4.251960] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ 4.260762] Mem abort info: [ 4.263556] ESR = 0x0000000096000004 [ 4.267308] EC = 0x25: DABT (current EL), IL = 32 bits [ 4.272624] SET = 0, FnV = 0 [ 4.275681] EA = 0, S1PTW = 0 [ 4.278822] FSC = 0x04: level 0 translation fault [ 4.283704] Data abort info: [ 4.286583] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 4.292074] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 4.297130] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 4.302445] [0000000000000000] user address but active_mm is swapper [ 4.308805] Internal error: Oops: 0000...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xgmg-7q7c-fhxx

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 5.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу