CVE-2017-15000 to CVE-2017-15999
181 CVEs with public proof-of-concept exploits.
- CVE-2017-150081 PoCPRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error…
- CVE-2017-150091 PoCPRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg…
- CVE-2017-150101 PoCA ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is…
- CVE-2017-150121 PoCOpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the…
- CVE-2017-150131 PoCOpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an…
- CVE-2017-150141 PoCOpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows…
- CVE-2017-150181 PoCLAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed…
- CVE-2017-150352 PoCsEmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
- CVE-2017-150482 PoCsStack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to…
- CVE-2017-150494 PoCsThe ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a…
- CVE-2017-150511 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject…
- CVE-2017-150521 PoCTeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a…
- CVE-2017-150531 PoCTeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a…
- CVE-2017-150541 PoCAn arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files…
- CVE-2017-150551 PoCTeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any…
- CVE-2017-150812 PoCsIn PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
- CVE-2017-150841 PoCThe web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
- CVE-2017-150951 PoCA deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated…
- CVE-2017-151181 PoCA stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an…
- CVE-2017-151201 PoCAn issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference…
- CVE-2017-151231 PoCA flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to…
- CVE-2017-151851 PoCplugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input,…
- CVE-2017-152202 PoCsFlexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../…
- CVE-2017-152212 PoCsASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.
- CVE-2017-152224 PoCsBuffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
- CVE-2017-152231 PoCDenial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory…
- CVE-2017-152321 PoClibjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
- CVE-2017-152351 PoCThe File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file…
- CVE-2017-152361 PoCTiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via…
- CVE-2017-152661 PoCIn GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
- CVE-2017-152671 PoCIn GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
- CVE-2017-152701 PoCThe PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be…
- CVE-2017-152711 PoCA use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior…
- CVE-2017-152761 PoCOpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an…
- CVE-2017-152772 PoCsReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file…
- CVE-2017-152842 PoCsCross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing…
- CVE-2017-152861 PoCSQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to consider certain cases where…
- CVE-2017-152872 PoCsThere is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or…
- CVE-2017-152911 PoCCross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers…
- CVE-2017-153021 PoCIn CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version 1.43) that can…
- CVE-2017-153032 PoCsIn CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program…
- CVE-2017-153051 PoCXSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
- CVE-2017-153571 PoCThe setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink…
- CVE-2017-153581 PoCRace condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors…
- CVE-2017-153591 PoCIn the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack:…
- CVE-2017-153601 PoCPRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect…
- CVE-2017-153613 PoCsThe Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34,…
- CVE-2017-153631 PoCDirectory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler…
- CVE-2017-153671 PoCBacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula…
- CVE-2017-153701 PoCThere is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to…
- CVE-2017-153711 PoCThere is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input…
- CVE-2017-153721 PoCThere is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted…
- CVE-2017-153731 PoCE-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
- CVE-2017-153742 PoCsShopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend…
- CVE-2017-153751 PoCMultiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The…
- CVE-2017-153761 PoCThe TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands…
- CVE-2017-153781 PoCSQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
- CVE-2017-153791 PoCAn authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
- CVE-2017-153801 PoCXSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.
- CVE-2017-153811 PoCSQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
- CVE-2017-153841 PoCrate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.
- CVE-2017-153941 PoCInsufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing…
- CVE-2017-153991 PoCA use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2017-154282 PoCsInsufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome…
- CVE-2017-155391 PoCSQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
- CVE-2017-155651 PoCIn Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF…
- CVE-2017-155781 PoCIn PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
- CVE-2017-155791 PoCIn PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
- CVE-2017-155803 PoCsosTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the…
- CVE-2017-155951 PoCAn issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack…
- CVE-2017-156002 PoCsIn GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.
- CVE-2017-156011 PoCIn GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c,…
- CVE-2017-156021 PoCIn GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in…
- CVE-2017-156131 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156141 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156151 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156161 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156171 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface…
- CVE-2017-156181 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156191 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156201 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156211 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156221 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156231 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156241 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156251 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156261 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156271 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156281 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156291 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156301 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156311 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156321 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156331 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156341 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name…
- CVE-2017-156351 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156361 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156371 PoCTP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the…
- CVE-2017-156391 PoCtasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds"…
- CVE-2017-156431 PoCAn active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows…
- CVE-2017-156441 PoCSSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for…
- CVE-2017-156451 PoCCSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute…
- CVE-2017-156461 PoCWebmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote…
- CVE-2017-156472 PoCsOn FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
- CVE-2017-156491 PoCnet/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger…
- CVE-2017-156541 PoCHighly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining…
- CVE-2017-156552 PoCsMultiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version…
- CVE-2017-156561 PoCPassword are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.
- CVE-2017-156622 PoCsIn Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a…
- CVE-2017-156633 PoCsIn Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a…
- CVE-2017-156642 PoCsIn Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a…
- CVE-2017-156652 PoCsIn Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a…
- CVE-2017-156671 PoCIn Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO…
- CVE-2017-156871 PoCDOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.
- CVE-2017-157081 PoCIn Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all…
- CVE-2017-157091 PoCWhen using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel…
- CVE-2017-157154 PoCsIn Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename,…
- CVE-2017-157271 PoCIn phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
- CVE-2017-157301 PoCIn phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
- CVE-2017-157341 PoCIn phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
- CVE-2017-157351 PoCIn phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
- CVE-2017-158061 PoCThe send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters…
- CVE-2017-158081 PoCIn phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
- CVE-2017-158101 PoCThe PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.
- CVE-2017-158782 PoCsA cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the…
- CVE-2017-158791 PoCCSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in…
- CVE-2017-158841 PoCIn HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin…
- CVE-2017-158851 PoCReflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via…
- CVE-2017-158892 PoCsCommand injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to…
- CVE-2017-159181 PoCSera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes…
- CVE-2017-159202 PoCsIn Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference…
- CVE-2017-159212 PoCsIn Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference…
- CVE-2017-159221 PoCIn GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
- CVE-2017-159241 PoCIn manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON…
- CVE-2017-159281 PoCIn the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the…
- CVE-2017-159311 PoCIn radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in…
- CVE-2017-159321 PoCIn radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in…
- CVE-2017-159447 PoCsKEVPalo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to…
- CVE-2017-159461 PoCIn the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request…
- CVE-2017-159471 PoCSimple ASC Content Management System v1.2 has XSS in the location field in the sign function, related to guestbook.asp, formgb.asp, and…
- CVE-2017-159481 PoCPerch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with…
- CVE-2017-159491 PoCXavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to…
- CVE-2017-159502 PoCsFlexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The…
- CVE-2017-159561 PoCConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
- CVE-2017-159571 PoCmy_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
- CVE-2017-159581 PoCD-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.
- CVE-2017-159592 PoCsAdult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.
- CVE-2017-159601 PoCArticle Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
- CVE-2017-159611 PoCiProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
- CVE-2017-159621 PoCiStock Management System 1.0 allows Arbitrary File Upload via user/profile.
- CVE-2017-159632 PoCsiTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.
- CVE-2017-159641 PoCJob Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
- CVE-2017-159652 PoCsThe NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create…
- CVE-2017-159662 PoCsThe Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.
- CVE-2017-159672 PoCsMailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to…
- CVE-2017-159682 PoCsMyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
- CVE-2017-159692 PoCsPG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.
- CVE-2017-159701 PoCPHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
- CVE-2017-159712 PoCsSame Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter,…
- CVE-2017-159722 PoCsSoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id…
- CVE-2017-159732 PoCsSokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
- CVE-2017-159742 PoCstPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
- CVE-2017-159751 PoCVastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.
- CVE-2017-159761 PoCZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.
- CVE-2017-159771 PoCProtected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
- CVE-2017-159781 PoCAROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
- CVE-2017-159791 PoCShareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
- CVE-2017-159801 PoCUS Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
- CVE-2017-159811 PoCResponsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
- CVE-2017-159821 PoCDynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
- CVE-2017-159831 PoCMyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
- CVE-2017-159841 PoCCreative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
- CVE-2017-159851 PoCBasic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
- CVE-2017-159861 PoCCPA Lead Reward Script allows SQL Injection via the username parameter.
- CVE-2017-159871 PoCFake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
- CVE-2017-159881 PoCNice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
- CVE-2017-159891 PoCOnline Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
- CVE-2017-159901 PoCPhp Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
- CVE-2017-159911 PoCVastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or…
- CVE-2017-159921 PoCWebsite Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
- CVE-2017-159931 PoCZomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.