Exploit Database

153,556 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-8304 WRITEUP MEDIUM
Accellion File Transfer Appliance < 9_12_40 - Cross-Site Scripting via OAuth Playground Callback URI
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
CVSS 6.1
CVE-2017-8788 WRITEUP MEDIUM
Accellion FTA <FTA_9_12_180 - Info Disclosure
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
CVSS 6.1
CVE-2017-8789 WRITEUP CRITICAL
Accellion File Transfer Appliance < 9_12_40 - SQL Injection via report_error.php Year Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
CVSS 9.8
CVE-2017-8790 WRITEUP CRITICAL
Accellion File Transfer Appliance < 9_12_40 - LDAP Injection via ldaptest.html Filter Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
CVSS 9.8
CVE-2017-8791 WRITEUP MEDIUM
Accellion FTA <FTA_9_12_180 - Auth Bypass
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.
CVSS 6.1
CVE-2017-8792 WRITEUP MEDIUM
Accellion File Transfer Appliance < 9_12_40 - Cross-Site Scripting via User Add Param Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
CVSS 6.1
CVE-2017-8793 WRITEUP HIGH
Accellion File Transfer Appliance < 9_12_40 - Same Origin Policy Bypass via acallow Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.
CVSS 8.8
CVE-2017-8794 WRITEUP CRITICAL
Accellion File Transfer Appliance < 9_12_40 - Server-Side Request Forgery via URL Validation Bypass
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
CVSS 10.0
CVE-2017-8795 WRITEUP MEDIUM
Accellion File Transfer Appliance < 9_12_40 - Cross-Site Scripting via SMTG Add Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
CVSS 6.1
CVE-2017-8796 WRITEUP CRITICAL
Accellion File Transfer Appliance < 9_12_40 - SQL Injection via app_id Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
CVSS 9.8
CVE-2017-9328 WRITEUP CRITICAL
TerraMaster Operating System < 3.0.33 - Remote Code Execution via GetTest.php Shell Metacharacter Injection
Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.
CVSS 9.8
CVE-2017-9615 WRITEUP CRITICAL
Cognito Software Moneyworks <8.0.3 - Info Disclosure
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.
CVSS 9.8
CVE-2018-1000653 WRITEUP CRITICAL
zzcms < 8.3 - SQL Injection in zt/top.php
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.
CVSS 9.8
CVE-2018-10363 WRITEUP HIGH
WpDevArt Booking calendar <2.2.2 - Info Disclosure
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
CVSS 7.5
CVE-2018-10641 WRITEUP HIGH
D-Link DIR-601 A1 1.02NA - Info Disclosure
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
CVSS 8.1
CVE-2018-10678 WRITEUP MEDIUM
MyBB 1.8.15 - Open Redirect via Target Attribute Handling
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
CVSS 6.1
CVE-2018-10723 WRITEUP CRITICAL
Directus 6.4.9 - Use of Hard-coded Credentials
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
CVSS 9.8
CVE-2018-10987 WRITEUP HIGH
diqee360_firmware - Authenticated Remote Code Execution via UDP Command 153
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute commands on the vacuum cleaner as root. The bug is in the function REQUEST_SET_WIFIPASSWD (UDP command 153). A crafted UDP packet runs "/mnt/skyeye/mode_switch.sh %s" with an attacker controlling the %s variable. In some cases, authentication can be achieved with the default password of 888888 for the admin account.
CVSS 7.5
CVE-2018-10988 WRITEUP HIGH
Diqee Diqee360 Firmware - Unauthenticated Remote Code Execution via Unsigned Firmware Update Script
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital signature, as root from the /mnt/sdcard/$PRO_NAME/upgrade.sh or /sdcard/upgrage_360/upgrade.sh pathname.
CVSS 7.8
CVE-2018-10997 WRITEUP CRITICAL
EtereWeb < 28.1.20 - Unauthenticated Blind SQL Injection via txUserName and txPassword Parameters
Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.
CVSS 9.8
CVE-2018-11240 WRITEUP CRITICAL
SoftCase T-Router Firmware - Unauthenticated Remote Code Execution via T-Router Protocol
An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in production builds as of Spring 2018.
CVSS 9.8
CVE-2018-11241 WRITEUP CRITICAL
SoftCase T-Router Firmware - Unauthenticated Arbitrary File Read and Write
An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary files on the system as root, as demonstrated by code execution after writing to a crontab file. This is fixed in production builds as of Spring 2018.
CVSS 9.8
CVE-2018-11541 WRITEUP CRITICAL
Sonus SBC 1000/2000/SWe Lite - Unauthenticated Privilege Escalation
A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
CVSS 9.8
CVE-2018-11542 WRITEUP CRITICAL
Sonus SBC 1000/2000/SWe Lite - Remote Code Execution
A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary commands via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
CVSS 9.8
CVE-2018-11543 WRITEUP HIGH
Sonus SBC 1000/2000/SWe Lite - Local File Inclusion via Web Interface
A Local File Inclusion (LFI) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the downloading of arbitrary files via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
CVSS 7.5