VYPR

CVEs

351,767 total · page 18 of 7,036

  • CVE-2017-17872CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

  • CVE-2017-17871CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

  • CVE-2017-17870CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.03

    The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

  • CVE-2017-17761CriDec 19, 2017
    risk 0.67cvss 9.8epss 0.05

    An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.

  • CVE-2017-17721CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.07

    CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.

  • CVE-2017-17651CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.03

    Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.

  • CVE-2017-17645CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.03

    Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.

  • CVE-2017-17643CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.02

    FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.

  • CVE-2017-17405HigDec 15, 2017
    risk 0.67cvss 8.8epss 0.89

    Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution.

  • CVE-2017-17648CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.01

    Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.

  • CVE-2017-17642CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.

  • CVE-2017-17641CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.

  • CVE-2017-17640CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.

  • CVE-2017-17639CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

  • CVE-2017-17638CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.

  • CVE-2017-17637CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

  • CVE-2017-17636CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.

  • CVE-2017-17635CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.

  • CVE-2017-17634CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2017-17633CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.

  • CVE-2017-17632CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2017-17631CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.

  • CVE-2017-17630CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Yoga Class Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17629CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.

  • CVE-2017-17628CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.

  • CVE-2017-17627CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.

  • CVE-2017-17626CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.

  • CVE-2017-17625CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.02

    Professional Service Script 1.0 has SQL Injection via the service-list city parameter.

  • CVE-2017-17624CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.

  • CVE-2017-17623CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.

  • CVE-2017-17622CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

  • CVE-2017-17621CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.

  • CVE-2017-17620CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.

  • CVE-2017-17619CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17618CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

  • CVE-2017-17617CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.

  • CVE-2017-17616CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Event Search Script 1.0 has SQL Injection via the /event-list city parameter.

  • CVE-2017-17614CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Food Order Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17613CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.

  • CVE-2017-17612CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.

  • CVE-2017-17611CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Doctor Search Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17610CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.

  • CVE-2017-17609CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.

  • CVE-2017-17608CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Child Care Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17607CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.

  • CVE-2017-17606CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17605CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.

  • CVE-2017-17604CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.

  • CVE-2017-17603CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.

  • CVE-2017-17602CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.