Show filters
469 Total Results
Displaying 271-280 of 469
Sort by:
Attacker Value
Unknown
CVE-2017-15549
Disclosure Date: January 05, 2018 (last updated November 26, 2024)
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any location on the server file system.
0
Attacker Value
Unknown
CVE-2017-15550
Disclosure Date: January 05, 2018 (last updated November 26, 2024)
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of the running vulnerable application via Path traversal.
0
Attacker Value
Unknown
CVE-2017-1000427
Disclosure Date: January 02, 2018 (last updated November 08, 2023)
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
0
Attacker Value
Unknown
CVE-2017-18010
Disclosure Date: January 01, 2018 (last updated November 26, 2024)
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
0
Attacker Value
Unknown
CVE-2017-17937
Disclosure Date: December 28, 2017 (last updated November 26, 2024)
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
0
Attacker Value
Unknown
CVE-2017-17936
Disclosure Date: December 28, 2017 (last updated November 26, 2024)
Vanguard Marketplace Digital Products PHP has CSRF via /search.
0
Attacker Value
Unknown
CVE-2017-17874
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
0
Attacker Value
Unknown
CVE-2017-17873
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
0
Attacker Value
Unknown
CVE-2017-17625
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
0
Attacker Value
Unknown
CVE-2017-17592
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
0