878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-12542
Integrated Lights-out 4 (iLO 4) General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2017 3 PoCs

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

CVE-2017-16877
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2017 1 PoC

ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

CVE-2017-1000170
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2017 1 PoC

jqueryFileTree 2.1.5 and older Directory Traversal

CVE-2017-1000163
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2017 1 PoC

The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.

CVE-2017-17762
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2017 1 PoC

XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.

CVE-2017-8229
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2017 2 PoCs

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function sub_436D6 in

CVE-2017-14135
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.1%
2017 0 PoCs

enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI.

CVE-2017-14524
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2017 1 PoC

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

CVE-2017-11512
ManageEngine ServiceDesk General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.9%
2017 CWE-22 0 PoCs

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

CVE-2017-0929
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2017 0 PoCs

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

CVE-2017-18638
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.8%
2017 2 PoCs

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVE-2017-11610
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2017 3 PoCs

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

CVE-2017-5982
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.4%
2017 2 PoCs

Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.

CVE-2023-36144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2023 1 PoC

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

CVE-2017-5983
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
6.4%
2017 2 PoCs

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

CVE-2017-11165
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2017 3 PoCs

dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.

CVE-2017-9833
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2017 3 PoCs

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

CVE-2017-14849
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2017 0 PoCs

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

CVE-2023-40924
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2023 1 PoC

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

CVE-2017-5871
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2017 2 PoCs

Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).