VYPR

CVEs

8,119 total · page 16 of 163

  • CVE-2017-15987CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.

  • CVE-2017-15986CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    CPA Lead Reward Script allows SQL Injection via the username parameter.

  • CVE-2017-15985CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.

  • CVE-2017-15984CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.

  • CVE-2017-15983CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

  • CVE-2017-15982CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

  • CVE-2017-15981CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

  • CVE-2017-15980CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.

  • CVE-2017-15979CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.

  • CVE-2017-15978CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

  • CVE-2017-15977CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.

  • CVE-2017-15976CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.

  • CVE-2017-15975CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.

  • CVE-2017-15974CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.04

    tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.

  • CVE-2017-15973CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.

  • CVE-2017-15972CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.

  • CVE-2017-15971CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.

  • CVE-2017-15970CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.

  • CVE-2017-15969CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.

  • CVE-2017-15968CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.

  • CVE-2017-15967CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.

  • CVE-2017-15966CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.04

    The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.

  • CVE-2017-15965CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.04

    The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

  • CVE-2017-15964CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.

  • CVE-2017-15963CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.

  • CVE-2017-15961CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.

  • CVE-2017-15960CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.

  • CVE-2017-15959CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.

  • CVE-2017-15958CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.

  • CVE-2016-5003CriOct 27, 2017
    risk 0.67cvss 9.8epss 0.42

    The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.

  • CVE-2014-2023CriOct 26, 2017
    risk 0.67cvss 9.8epss 0.09

    Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in mobiquo/functions/.

  • CVE-2017-15081CriOct 24, 2017
    risk 0.67cvss 9.8epss 0.07

    In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

  • CVE-2017-10352CriOct 19, 2017
    risk 0.67cvss 9.9epss 0.28

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).

  • CVE-2017-15579CriOct 18, 2017
    risk 0.67cvss 9.8epss 0.00

    In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.

  • CVE-2017-12629CriOct 14, 2017
    risk 0.67cvss 9.8epss 0.94

    Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

  • CVE-2015-2147CriOct 6, 2017
    risk 0.67cvss 9.8epss 0.00

    Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.

  • CVE-2017-6089CriOct 3, 2017
    risk 0.67cvss 9.8epss 0.03

    SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.

  • CVE-2017-14493CriOct 3, 2017
    risk 0.67cvss 9.8epss 0.05

    Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.

  • CVE-2017-14738CriSep 30, 2017
    risk 0.67cvss 9.8epss 0.06

    FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).

  • CVE-2017-14507CriSep 29, 2017
    risk 0.67cvss 9.8epss 0.08

    Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.

  • CVE-2017-14703CriSep 26, 2017
    risk 0.67cvss 9.8epss 0.01

    SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.

  • CVE-2017-12930CriSep 21, 2017
    risk 0.67cvss 9.8epss 0.03

    SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.

  • CVE-2017-12611CriSep 20, 2017
    risk 0.67cvss 9.8epss 0.94

    In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

  • CVE-2017-6315CriSep 19, 2017
    risk 0.67cvss 9.8epss 0.09

    Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.

  • CVE-2017-14396CriSep 12, 2017
    risk 0.67cvss 9.8epss 0.02

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

  • CVE-2015-8351CriSep 11, 2017
    risk 0.67cvss 9.0epss 0.69

    PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.

  • CVE-2017-3897CriSep 1, 2017
    risk 0.67cvss 9.8epss 0.04

    A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

  • CVE-2014-9558CriAug 28, 2017
    risk 0.67cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in SmartCMS v.2.

  • CVE-2015-7853CriAug 7, 2017
    risk 0.67cvss 9.8epss 0.41

    The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value.

  • CVE-2017-11494CriAug 2, 2017
    risk 0.67cvss 9.8epss 0.03

    SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.