Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 567

Количество 359 567

github логотип

GHSA-xgj6-2p43-6fvx

больше 4 лет назад

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-xgj5-fv7f-m344

больше 4 лет назад

Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.

EPSS: Низкий
github логотип

GHSA-xgj4-xv99-p98g

больше 4 лет назад

Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.

EPSS: Низкий
github логотип

GHSA-xgj4-hqhc-7c6f

больше 4 лет назад

Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port assignment in the management interface. NOTE: this can be leveraged by non-authenticated attackers using CVE-2009-4657.

EPSS: Низкий
github логотип

GHSA-xgj4-2hrf-j4xg

больше 2 лет назад

Cross-site scripting in Survey Creator

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgj3-rr8r-f3c6

около 3 лет назад

Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgj3-g5r2-m8rf

около 2 месяцев назад

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xghx-gh8p-84h2

больше 4 лет назад

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xghx-f376-x86r

около 2 месяцев назад

Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitization in the string-concatenated filter expression passed to the Hibernate findList() call to extract sensitive data such as administrator password hashes and, with sufficient database privileges, perform file-write operations enabling remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-11 (UTC).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xghw-p77p-3r7x

5 дней назад

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

EPSS: Низкий
github логотип

GHSA-xghw-h4mr-43qx

6 месяцев назад

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xghw-7p5g-wmjc

больше 1 года назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xghw-5mm2-r3q7

больше 3 лет назад

An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic application traffic, allowing an unauthenticated network-based attacker to send traffic to the target device using the JDPI-Decoder, designed to inspect dynamic application traffic and take action upon this traffic, to instead begin to not take action and to pass the traffic through. An example session can be seen by running the following command and evaluating the output. user@device# run show security flow session source-prefix <address/mask> extensive Session ID: <session ID>, Status: Normal, State: Active Policy name: <name of policy> Dynamic application: junos:UNKNOWN, <<<<< LOOK HERE Please note, the JDPI-Decoder and the AppID SigPack are both affected and both must be upgraded along with the operating system ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xghw-4j4f-7p37

больше 4 лет назад

The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/parameters and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.

EPSS: Низкий
github логотип

GHSA-xghr-r2p4-w9qp

больше 4 лет назад

Buffer overflow in Dirapix.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xghr-p26r-9675

больше 3 лет назад

This issue affects: Terminal Operating System versions before 5.0.13

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xghr-m3mr-m6m9

больше 4 лет назад

A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.

EPSS: Низкий
github логотип

GHSA-xghr-g5w9-xwr9

около 1 года назад

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xghr-2v47-fqx8

около 1 месяца назад

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xghq-r485-w5jv

больше 4 лет назад

Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgj6-2p43-6fvx

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

CVSS3: 7.2
17%
Средний
больше 4 лет назад
github логотип
GHSA-xgj5-fv7f-m344

Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgj4-xv99-p98g

Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xgj4-hqhc-7c6f

Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port assignment in the management interface. NOTE: this can be leveraged by non-authenticated attackers using CVE-2009-4657.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgj4-2hrf-j4xg

Cross-site scripting in Survey Creator

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xgj3-rr8r-f3c6

Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xgj3-g5r2-m8rf

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xghx-gh8p-84h2

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xghx-f376-x86r

Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitization in the string-concatenated filter expression passed to the Hibernate findList() call to extract sensitive data such as administrator password hashes and, with sufficient database privileges, perform file-write operations enabling remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-11 (UTC).

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xghw-p77p-3r7x

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

5 дней назад
github логотип
GHSA-xghw-h4mr-43qx

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xghw-7p5g-wmjc

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

CVSS3: 3.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xghw-5mm2-r3q7

An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic application traffic, allowing an unauthenticated network-based attacker to send traffic to the target device using the JDPI-Decoder, designed to inspect dynamic application traffic and take action upon this traffic, to instead begin to not take action and to pass the traffic through. An example session can be seen by running the following command and evaluating the output. user@device# run show security flow session source-prefix <address/mask> extensive Session ID: <session ID>, Status: Normal, State: Active Policy name: <name of policy> Dynamic application: junos:UNKNOWN, <<<<< LOOK HERE Please note, the JDPI-Decoder and the AppID SigPack are both affected and both must be upgraded along with the operating system ...

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xghw-4j4f-7p37

The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/parameters and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xghr-r2p4-w9qp

Buffer overflow in Dirapix.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xghr-p26r-9675

This issue affects: Terminal Operating System versions before 5.0.13

CVSS3: 9.8
14%
Средний
больше 3 лет назад
github логотип
GHSA-xghr-m3mr-m6m9

A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xghr-g5w9-xwr9

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xghr-2v47-fqx8

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
github логотип
GHSA-xghq-r485-w5jv

Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу