Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xghp-mpq3-hr44

около 2 месяцев назад

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation of the argument editid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xghp-9m6j-2mx2

25 дней назад

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xghp-74wc-wjg3

почти 2 года назад

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xghp-2wj5-qcmq

больше 4 лет назад

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xghm-ffg2-3jq3

больше 4 лет назад

ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql.

EPSS: Низкий
github логотип

GHSA-xghm-345m-3fvj

больше 4 лет назад

Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) Admin/frmSite.aspx, (2) Default.aspx, (3) Services/SiteAdmin.asmx, or (4) Client/frmViewReports.aspx; certain cookies to (5) Services/SiteAdmin.asmx or (6) login.aspx; the Referer HTTP header to (7) Services/SiteAdmin.asmx or (8) login.aspx; or (9) the User-Agent HTTP header to Services/SiteAdmin.asmx.

EPSS: Низкий
github логотип

GHSA-xghj-v4x3-gwvf

около 4 лет назад

In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

EPSS: Средний
github логотип

GHSA-xghh-rrw6-jc8f

около 4 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xghh-hvm9-x9wr

2 месяца назад

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xghg-58h4-gjjw

около 4 лет назад

The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.

EPSS: Низкий
github логотип

GHSA-xghf-rq5q-xgj7

больше 4 лет назад

Multiple interpretation error in Ukrainian National Antivirus (UNA) 1.83.2.16 with kernel 265 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."

EPSS: Низкий
github логотип

GHSA-xghf-rfpw-9v3h

больше 4 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility, which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20 mishandling in the header function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xghf-952v-933j

больше 2 лет назад

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xgh9-pwwg-jfvx

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xgh9-482q-m2w6

больше 1 года назад

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgh6-xj95-pp64

около 4 лет назад

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgh6-mwxq-8jp5

больше 4 лет назад

An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of higher-privileged ones (such as xpadmin).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgh6-cx5m-pwqv

почти 3 года назад

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xgh6-85xh-479p

почти 6 лет назад

Regular Expression Denial of Service in npm-user-validate

EPSS: Низкий
github логотип

GHSA-xgh6-7v4c-vr2f

почти 4 года назад

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-37961, CVE-2022-38009.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xghp-mpq3-hr44

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation of the argument editid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xghp-9m6j-2mx2

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 6.5
1%
Низкий
25 дней назад
github логотип
GHSA-xghp-74wc-wjg3

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-xghp-2wj5-qcmq

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xghm-ffg2-3jq3

ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xghm-345m-3fvj

Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) Admin/frmSite.aspx, (2) Default.aspx, (3) Services/SiteAdmin.asmx, or (4) Client/frmViewReports.aspx; certain cookies to (5) Services/SiteAdmin.asmx or (6) login.aspx; the Referer HTTP header to (7) Services/SiteAdmin.asmx or (8) login.aspx; or (9) the User-Agent HTTP header to Services/SiteAdmin.asmx.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xghj-v4x3-gwvf

In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

27%
Средний
около 4 лет назад
github логотип
GHSA-xghh-rrw6-jc8f

Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xghh-hvm9-x9wr

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xghg-58h4-gjjw

The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xghf-rq5q-xgj7

Multiple interpretation error in Ukrainian National Antivirus (UNA) 1.83.2.16 with kernel 265 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xghf-rfpw-9v3h

The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility, which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20 mishandling in the header function.

CVSS3: 6.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xghf-952v-933j

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgh9-pwwg-jfvx

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-xgh9-482q-m2w6

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgh6-xj95-pp64

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xgh6-mwxq-8jp5

An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of higher-privileged ones (such as xpadmin).

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgh6-cx5m-pwqv

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

CVSS3: 7.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-xgh6-85xh-479p

Regular Expression Denial of Service in npm-user-validate

почти 6 лет назад
github логотип
GHSA-xgh6-7v4c-vr2f

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-37961, CVE-2022-38009.

CVSS3: 8.8
2%
Низкий
почти 4 года назад

Уязвимостей на страницу