| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-17872 | Cri | 0.67 | 9.8 | 0.01 | Dec 27, 2017 | The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action. | |
| CVE-2017-17871 | Cri | 0.67 | 9.8 | 0.01 | Dec 27, 2017 | The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter. | |
| CVE-2017-17870 | Cri | 0.67 | 9.8 | 0.03 | Dec 27, 2017 | The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. | |
| CVE-2017-17761 | Cri | 0.67 | 9.8 | 0.05 | Dec 19, 2017 | An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response. | |
| CVE-2017-17721 | Cri | 0.67 | 9.8 | 0.07 | Dec 18, 2017 | CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter. | |
| CVE-2017-17651 | Cri | 0.67 | 9.8 | 0.03 | Dec 18, 2017 | Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter. | |
| CVE-2017-17645 | Cri | 0.67 | 9.8 | 0.03 | Dec 18, 2017 | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | |
| CVE-2017-17643 | Cri | 0.67 | 9.8 | 0.02 | Dec 18, 2017 | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. | |
| CVE-2017-17405 | Hig | 0.67 | 8.8 | 0.89 | Dec 15, 2017 | Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution. | |
| CVE-2017-17648 | Cri | 0.67 | 9.8 | 0.01 | Dec 13, 2017 | Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. | |
| CVE-2017-17642 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. | |
| CVE-2017-17641 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | |
| CVE-2017-17640 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | |
| CVE-2017-17639 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | |
| CVE-2017-17638 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | |
| CVE-2017-17637 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | |
| CVE-2017-17636 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | |
| CVE-2017-17635 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | |
| CVE-2017-17634 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |
| CVE-2017-17633 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter. | |
| CVE-2017-17632 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |
| CVE-2017-17631 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | |
| CVE-2017-17630 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17629 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | |
| CVE-2017-17628 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | |
| CVE-2017-17627 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | |
| CVE-2017-17626 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. | |
| CVE-2017-17625 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. | |
| CVE-2017-17624 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | |
| CVE-2017-17623 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | |
| CVE-2017-17622 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. | |
| CVE-2017-17621 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. | |
| CVE-2017-17620 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. | |
| CVE-2017-17619 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17618 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. | |
| CVE-2017-17617 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. | |
| CVE-2017-17616 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Event Search Script 1.0 has SQL Injection via the /event-list city parameter. | |
| CVE-2017-17614 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17613 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. | |
| CVE-2017-17612 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. | |
| CVE-2017-17611 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Doctor Search Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17610 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter. | |
| CVE-2017-17609 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. | |
| CVE-2017-17608 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Child Care Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17607 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | |
| CVE-2017-17606 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17605 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. | |
| CVE-2017-17604 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. | |
| CVE-2017-17603 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | |
| CVE-2017-17602 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. |
- risk 0.67cvss 9.8epss 0.01
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
- risk 0.67cvss 9.8epss 0.01
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
- risk 0.67cvss 9.8epss 0.03
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
- risk 0.67cvss 9.8epss 0.05
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.
- risk 0.67cvss 9.8epss 0.07
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
- risk 0.67cvss 9.8epss 0.03
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
- risk 0.67cvss 9.8epss 0.03
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
- risk 0.67cvss 9.8epss 0.02
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
- risk 0.67cvss 8.8epss 0.89
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution.
- risk 0.67cvss 9.8epss 0.01
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
- risk 0.67cvss 9.8epss 0.03
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
- risk 0.67cvss 9.8epss 0.03
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
- risk 0.67cvss 9.8epss 0.03
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
- risk 0.67cvss 9.8epss 0.03
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
- risk 0.67cvss 9.8epss 0.03
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
- risk 0.67cvss 9.8epss 0.03
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
- risk 0.67cvss 9.8epss 0.03
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
- risk 0.67cvss 9.8epss 0.03
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
- risk 0.67cvss 9.8epss 0.03
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
- risk 0.67cvss 9.8epss 0.03
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
- risk 0.67cvss 9.8epss 0.03
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
- risk 0.67cvss 9.8epss 0.03
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
- risk 0.67cvss 9.8epss 0.03
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
- risk 0.67cvss 9.8epss 0.02
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
- risk 0.67cvss 9.8epss 0.03
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
- risk 0.67cvss 9.8epss 0.04
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
- risk 0.67cvss 9.8epss 0.04
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
- risk 0.67cvss 9.8epss 0.03
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
- risk 0.67cvss 9.8epss 0.04
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
- risk 0.67cvss 9.8epss 0.03
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Food Order Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.
- risk 0.67cvss 9.8epss 0.04
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
- risk 0.67cvss 9.8epss 0.03
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
- risk 0.67cvss 9.8epss 0.03
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Child Care Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
- risk 0.67cvss 9.8epss 0.03
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
- risk 0.67cvss 9.8epss 0.03
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
- risk 0.67cvss 9.8epss 0.03
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.