CVE-2016-11000 to CVE-2016-11999
9 CVEs with public proof-of-concept exploits.
- CVE-2016-110051 PoCThe instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS.
- CVE-2016-110121 PoCThe sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.
- CVE-2016-110143 PoCsNETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
- CVE-2016-110153 PoCsNETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL…
- CVE-2016-110162 PoCsNETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
- CVE-2016-110172 PoCsThe application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS…
- CVE-2016-110212 PoCsKEVsetSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand…
- CVE-2016-110221 PoCNETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges…
- CVE-2016-110851 PoCphp/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via…