7.5
    High

    CVE-2017-17876

    Last Modified: 26 Dec 2017

    Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.

    Source:Ihsan Sencan
    Published:26 Dec 2017
    9.8
    Critical

    CVE-2017-17875

    Last Modified: 26 Dec 2017

    The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

    Source:Ihsan Sencan
    Published:26 Dec 2017
    8.8
    High

    CVE-2017-17874

    Last Modified: 26 Dec 2017

    Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.

    Source:Ihsan Sencan
    Published:24 Dec 2017
    9.8
    Critical

    CVE-2017-17873

    Last Modified: 26 Dec 2017

    Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

    Source:Ihsan Sencan
    Published:24 Dec 2017
    9.8
    Critical

    CVE-2017-17872

    Last Modified: 26 Dec 2017

    The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

    Source:Ihsan Sencan
    Published:24 Dec 2017
    9.8
    Critical

    CVE-2017-17871

    Last Modified: 26 Dec 2017

    The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

    Source:Ihsan Sencan
    Published:24 Dec 2017
    9.8
    Critical

    CVE-2017-17870

    Last Modified: 26 Dec 2017

    The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

    Source:Ihsan Sencan
    Published:23 Dec 2017
    8.8
    High

    CVE-2017-17867

    Last Modified: 4 Jan 2018

    Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.

    Source:neonsea
    Published:4 Jan 2018
    9.8
    Critical

    CVE-2017-17849

    Last Modified: 26 Dec 2017

    A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.

    Source:Aloyce J. Makalanga
    Published:24 Dec 2017
    9.8
    Critical

    CVE-2017-17761

    Last Modified: 15 Feb 2018

    An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.

    Source:SecuriTeam
    Published:19 Dec 2017
    9.8
    Critical

    CVE-2017-17759

    Last Modified: 21 Dec 2017

    Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).

    Source:Information Paradox
    Published:19 Dec 2017
    6.1
    Medium

    CVE-2017-17752

    Last Modified: 20 Dec 2017

    Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.

    Source:Aloyce J. Makalanga
    Published:20 Dec 2017
    9.8
    Critical

    CVE-2017-17739

    Last Modified: 19 Dec 2017

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.

    Source:Information Paradox
    Published:18 Dec 2017
    7.5
    High

    CVE-2017-17738

    Last Modified: 19 Dec 2017

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.

    Source:Information Paradox
    Published:18 Dec 2017
    6.1
    Medium

    CVE-2017-17737

    Last Modified: 19 Dec 2017

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.

    Source:Information Paradox
    Published:18 Dec 2017
    9.8
    Critical

    CVE-2017-17736

    Last Modified: 19 Dec 2025

    Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

    Published:23 Mar 2018
    9.8
    Critical

    CVE-2017-17721

    Last Modified: 22 Dec 2017

    CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.

    Source:Rajwinder Singh
    Published:18 Dec 2017
    7.5
    High

    CVE-2017-17692

    Last Modified: 20 Dec 2017

    Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.

    Source:Dhiraj Mishra
    Published:21 Dec 2017
    9.8
    Critical

    CVE-2017-17672

    Last Modified: 1 Oct 2019

    In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which is a publicly exposed API. This is exploited with the templateidlist parameter to ajax/api/template/cacheTemplates.

    Source:SecuriTeam
    Published:14 Dec 2017
    9.8
    Critical

    CVE-2017-17651

    Last Modified: 14 Dec 2017

    Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.

    Source:Ihsan Sencan
    Published:18 Dec 2017
    6.1
    Medium

    CVE-2017-17649

    Last Modified: 14 Dec 2017

    Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.

    Source:Ihsan Sencan
    Published:18 Dec 2017
    9.8
    Critical

    CVE-2017-17648

    Last Modified: 13 Dec 2017

    Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17645

    Last Modified: 14 Dec 2017

    Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.

    Source:Ihsan Sencan
    Published:18 Dec 2017
    9.8
    Critical

    CVE-2017-17643

    Last Modified: 14 Dec 2017

    FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.

    Source:Ihsan Sencan
    Published:18 Dec 2017
    9.8
    Critical

    CVE-2017-17642

    Last Modified: 13 Dec 2017

    Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17641

    Last Modified: 13 Dec 2017

    Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17640

    Last Modified: 13 Dec 2017

    Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17639

    Last Modified: 13 Dec 2017

    Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17638

    Last Modified: 13 Dec 2017

    Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17637

    Last Modified: 13 Dec 2017

    Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17636

    Last Modified: 13 Dec 2017

    MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17635

    Last Modified: 13 Dec 2017

    MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17634

    Last Modified: 13 Dec 2017

    Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17633

    Last Modified: 13 Dec 2017

    Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17632

    Last Modified: 13 Dec 2017

    Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17631

    Last Modified: 13 Dec 2017

    Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17630

    Last Modified: 13 Dec 2017

    Yoga Class Script 1.0 has SQL Injection via the /list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17629

    Last Modified: 13 Dec 2017

    Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17628

    Last Modified: 20 Nov 2018

    Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17627

    Last Modified: 13 Dec 2017

    Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17626

    Last Modified: 13 Dec 2017

    Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17625

    Last Modified: 13 Dec 2017

    Professional Service Script 1.0 has SQL Injection via the service-list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17624

    Last Modified: 13 Dec 2017

    PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17623

    Last Modified: 13 Dec 2017

    Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17622

    Last Modified: 13 Dec 2017

    Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17621

    Last Modified: 13 Dec 2017

    Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17620

    Last Modified: 13 Dec 2017

    Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17619

    Last Modified: 13 Dec 2017

    Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17618

    Last Modified: 13 Dec 2017

    Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17617

    Last Modified: 13 Dec 2017

    Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017