3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-17043
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.0%
2017 2 PoCs

The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly.

CVE-2017-10974
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2017 2 PoCs

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

CVE-2017-18487
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.

CVE-2017-18494
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.

CVE-2017-16894
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.8%
2017 2 PoCs

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVE-2017-6478
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2017 1 PoC

paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).

CVE-2017-4011
Network Data Loss Prevention (NDLP) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.9%
2017 1 PoC

Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.

CVE-2017-11444
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.3%
2017 0 PoCs

Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

CVE-2017-1000028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2017 4 PoCs

Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.

CVE-2017-18518
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.

CVE-2017-17762
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2017 1 PoC

XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.

CVE-2017-14942
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2017 1 PoC

Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.

CVE-2017-18024
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2017 1 PoC

AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.

CVE-2017-8229
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2017 2 PoCs

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function sub_436D6 in

CVE-2017-15715
Apache HTTP Server Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2017 2 PoCs

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

CVE-2017-18562
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.

CVE-2017-8046
Pivotal Spring Data REST and Spring Boot Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2017 8 PoCs

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

CVE-2017-18529
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.

CVE-2017-11107
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

CVE-2017-6090
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.9%
2017 4 PoCs

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.