Exploit Database

153,556 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-15582 WRITEUP HIGH
Diary with lock 4.72 - Use of Hard-coded Credentials in AES Encryption
In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.
CVSS 7.5
CVE-2017-16242 WRITEUP MEDIUM
MECO USB Memory Stick - Auth Bypass
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on the PCB to unlock the key and get access to the data without possessing the required fingerprint.
CVSS 6.8
CVE-2017-16514 WRITEUP MEDIUM
WebsiteBaker 2.10.0 - Stored Cross-Site Scripting in Droplet Description and Site Title
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.
CVSS 6.1
CVE-2017-16765 WRITEUP MEDIUM
D-Link DWR-933 1.00(WW)B17 - Cross-Site Scripting via cgi-bin/gui.cgi
XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
CVSS 6.1
CVE-2017-16870 WRITEUP HIGH
UpdraftPlus < 1.13.12 - Authenticated Server-Side Request Forgery via updraft_ajax_handler
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary
CVSS 8.1
CVE-2017-16871 WRITEUP HIGH
UpdraftPlus < 1.13.12 - Authenticated Remote Code Execution via Race Condition in plupload_action
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundary
CVSS 8.1
CVE-2017-17561 WRITEUP HIGH
SeaCMS 6.56 - Authenticated Remote Code Execution via Admin Ping Token
SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.
CVSS 7.2
CVE-2017-17762 WRITEUP HIGH
Episerver 7 - Blind XML External Entity Injection
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
CVSS 7.5
CVE-2017-18376 WRITEUP HIGH
TheHive < 2.13.4 and 3.x < 3.3.1 - Privilege Escalation via User API
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
CVSS 8.8
CVE-2017-20202 WRITEUP CRITICAL
Web Developer for Chrome <0.4.9 - Code Injection
Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, displayed fake “repair” alerts that redirected users to affiliate programs, and attempted to harvest credentials when users logged in. Injected components enumerate common banner sizes for substitution, replace third-party ad calls, and redirect victim traffic to affiliate landing pages. Potential impacts include user-level code execution in the browser context, large-scale ad fraud and traffic hijacking, credential theft, and exposure to additional payloads delivered by the actor. The compromise was reported on by the maintainer of Web Developer for Chrome on August 2, 2017 and remediated in v0.5.0.
CVE-2017-6513 WRITEUP CRITICAL
WHMCS Reseller Module V2 <2.9.1.0 - Privilege Escalation
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
CVSS 9.9
CVE-2017-6564 WRITEUP MEDIUM
Franklin Fueling TS-550 evo Firmware 2.3.0.7332 - Unauthenticated Sensitive File Download via idSourceFileName Parameter
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.
CVSS 6.5
CVE-2017-6565 WRITEUP HIGH
Franklin Fueling Systems TS-550 evo 2.3.0.7332 - Unauthenticated Arbitrary File Upload via roleDiag User
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload.
CVSS 8.8
CVE-2017-7187 WRITEUP HIGH
Linux kernel <4.10.4 - Buffer Overflow
The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function.
CVSS 7.8
CVE-2017-7220 WRITEUP HIGH
OpenText Documentum Content Server - Privilege Escalation
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532.
CVSS 8.8
CVE-2017-7220 WRITEUP HIGH
OpenText Documentum Content Server - Privilege Escalation
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532.
CVSS 8.8
CVE-2017-7229 WRITEUP CRITICAL
Vaultive Office 365 Security < 4.5.21 - DoS & Info Disclosure via PGP/MIME Mismanagement
PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to 'Content-Type: text/plain' - this results in the encrypted message being structured in such a way that most PGP/MIME-capable mail user agents are unable to decrypt it cleanly. The outcome is that encrypted mail passing through this device does not work (Denial of Service), and a common real-world consequence is a request to resend the mail in the clear (Information Disclosure).
CVSS 9.1
CVE-2017-7253 WRITEUP HIGH
Dahua IP Camera <3.200.0001.6 - Info Disclosure
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object encountered has a "Component error: login challenge!" message. The second JSON object encountered has a result indicating a successful admin login.
CVSS 8.8
CVE-2017-7290 WRITEUP HIGH
XOOPS < 2.5.8.1 - Authenticated SQL Injection via findusers.php url Parameter
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
CVSS 7.2
CVE-2017-7295 WRITEUP HIGH
Contiki Operating System 3.0 - Use After Free
An issue was discovered in Contiki Operating System 3.0. A use-after-free vulnerability exists in httpd-simple.c in cc26xx-web-demo httpd, where upon a connection close event, the http_state structure was not deallocated properly, resulting in a NULL pointer dereference in the output processing function. This resulted in a board crash, which can be used to perform denial of service.
CVSS 7.5
CVE-2017-7296 WRITEUP MEDIUM
Contiki 3.0 - Stored Cross-Site Scripting in MQTT/IBM Cloud Config Page
An issue was discovered in Contiki Operating System 3.0. A Persistent XSS vulnerability is present in the MQTT/IBM Cloud Config page (aka mqtt.html) of cc26xx-web-demo. The cc26xx-web-demo features a webserver that runs on a constrained device. That particular page allows a user to remotely configure that device's operation by sending HTTP POST requests. The vulnerability consists of improper input sanitisation of the text fields on the MQTT/IBM Cloud config page, allowing for JavaScript code injection.
CVSS 6.1
CVE-2017-7626 WRITEUP MEDIUM
Smart Related Articles 1.1 - Cross-Site Scripting via GET Parameters in dialog.php
The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).
CVSS 6.1
CVE-2017-7627 WRITEUP MEDIUM
Smart related articles 1.1 - Unauthenticated Arbitrary File Access via dialog.php
The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).
CVSS 5.3
CVE-2017-7628 WRITEUP CRITICAL
Smart related articles 1.1 - SQL Injection via search_cats POST Parameter
The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).
CVSS 9.8
CVE-2017-8303 WRITEUP CRITICAL
Accellion File Transfer Appliance < 9_12_180 - Remote Code Execution via seos/1000/find.api Method Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
CVSS 9.8