CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2011-4955

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-5257

    Last Modified: 20 Apr 2025

    In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of the currently-logged on user.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-5254

    Last Modified: 20 Apr 2025

    In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-5255

    Last Modified: 20 Apr 2025

    In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-5256

    Last Modified: 20 Apr 2025

    In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-5259

    Last Modified: 20 Apr 2025

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-5261

    Last Modified: 20 Apr 2025

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to all authenticated users.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-5258

    Last Modified: 20 Apr 2025

    In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certain SNMP OIDs, serve it via HTTP, and the affected device will perform a configuration restore using the attacker's supplied config file, including the inserted XSS strings.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-5260

    Last Modified: 20 Apr 2025

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.

    Published: 20 Dec 2017
    8
    High

    CVE-2017-5262

    Last Modified: 20 Apr 2025

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.

    Published: 20 Dec 2017
    8
    High

    CVE-2017-5263

    Last Modified: 20 Apr 2025

    Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.

    Published: 20 Dec 2017
    9.8
    Critical

    CVE-2012-2576

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

    Published: 20 Dec 2017
    6.5
    Medium

    CVE-2017-17747

    Last Modified: 20 Apr 2025

    Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-17745

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.

    Published: 20 Dec 2017
    6.8
    Medium

    CVE-2017-17746

    Last Modified: 20 Apr 2025

    Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the authentication applies to the IP address of the NAT gateway, and any user behind that NAT gateway is also treated as authenticated.

    Published: 20 Dec 2017
    9.8
    Critical

    CVE-2017-6094

    Last Modified: 20 Apr 2025

    CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN interface and a certain "chk" value (48bit) derived from the MAC. The algorithm used to compute the "chk" was disclosed by reverse engineering the CPE's firmware. As a result, it is possible to forge valid "chk" values for any given MAC address and therefore receive the configuration settings of other subscribers' CPEs. The configuration settings often contain sensitive values, for example credentials (username/password) for VoIP services. This issue affects Genexis B.V. GAPS up to 7.2.

    Published: 20 Dec 2017
    8.6
    High

    CVE-2017-16717

    Last Modified: 20 Apr 2025

    A Heap-based Buffer Overflow issue was discovered in WECON LeviStudio HMI. The heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.

    Published: 20 Dec 2017
    9.8
    Critical

    CVE-2017-16725

    Last Modified: 20 Apr 2025

    A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-16731

    Last Modified: 20 Apr 2025

    An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.

    Published: 20 Dec 2017
    5.3
    Medium

    CVE-2017-16733

    Last Modified: 20 Apr 2025

    A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.

    Published: 20 Dec 2017
    5.3
    Medium

    CVE-2017-16735

    Last Modified: 20 Apr 2025

    A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error in the database log.

    Published: 20 Dec 2017
    4.3
    Medium

    CVE-2017-1257

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

    Published: 20 Dec 2017
    5.7
    Medium

    CVE-2017-15532

    Last Modified: 20 Apr 2025

    Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to access arbitrary files and directories stored on the file system including application source code or configuration and critical system files.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-12072

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-1494

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14962

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-1600

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132613.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-1746

    Last Modified: 20 Apr 2025

    IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-1751

    Last Modified: 20 Apr 2025

    IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14963

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x83000058.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14968

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x830000c4, a related issue to CVE-2017-17113.

    Published: 20 Dec 2017
    5.4
    Medium

    CVE-2017-1266

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.

    Published: 20 Dec 2017
    3.3
    Low

    CVE-2017-1270

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 124745.

    Published: 20 Dec 2017
    5.3
    Medium

    CVE-2017-1423

    Last Modified: 20 Apr 2025

    IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14964

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300005c.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14965

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x830000cc.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14966

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x830000c0.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14967

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x83000080.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-14969

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x83000084, a related issue to CVE-2017-17114.

    Published: 20 Dec 2017
    5.5
    Medium

    CVE-2017-1595

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.

    Published: 20 Dec 2017
    5.5
    Medium

    CVE-2017-1596

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132550.

    Published: 20 Dec 2017
    7.5
    High

    CVE-2017-1598

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-1631

    Last Modified: 20 Apr 2025

    IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140.

    Published: 20 Dec 2017
    8.1
    High

    CVE-2017-1694

    Last Modified: 20 Apr 2025

    IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-1696

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 134178.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-1757

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.

    Published: 20 Dec 2017
    3.3
    Low

    CVE-2017-1261

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.

    Published: 20 Dec 2017
    6.1
    Medium

    CVE-2017-1262

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-17476

    Last Modified: 20 Apr 2025

    Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.

    Published: 20 Dec 2017
    6.1
    Medium

    CVE-2017-17752

    Last Modified: 20 Apr 2025

    Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.

    Published: 20 Dec 2017