9.8
    Critical

    CVE-2017-17616

    Last Modified: 13 Dec 2017

    Event Search Script 1.0 has SQL Injection via the /event-list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    8.8
    High

    CVE-2017-17615

    Last Modified: 13 Dec 2017

    Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17614

    Last Modified: 13 Dec 2017

    Food Order Script 1.0 has SQL Injection via the /list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17613

    Last Modified: 13 Dec 2017

    Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17612

    Last Modified: 29 Jan 2018

    Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17611

    Last Modified: 13 Dec 2017

    Doctor Search Script 1.0 has SQL Injection via the /list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17610

    Last Modified: 13 Dec 2017

    E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17609

    Last Modified: 13 Dec 2017

    Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17608

    Last Modified: 13 Dec 2017

    Child Care Script 1.0 has SQL Injection via the /list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17607

    Last Modified: 13 Dec 2017

    CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17606

    Last Modified: 13 Dec 2017

    Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17605

    Last Modified: 13 Dec 2017

    Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17604

    Last Modified: 13 Dec 2017

    Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17603

    Last Modified: 13 Dec 2017

    Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17602

    Last Modified: 13 Dec 2017

    Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17601

    Last Modified: 13 Dec 2017

    Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17600

    Last Modified: 13 Dec 2017

    Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17599

    Last Modified: 13 Dec 2017

    Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17598

    Last Modified: 13 Dec 2017

    Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17597

    Last Modified: 13 Dec 2017

    Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17596

    Last Modified: 13 Dec 2017

    Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17595

    Last Modified: 13 Dec 2017

    Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17594

    Last Modified: 13 Dec 2017

    DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    7.5
    High

    CVE-2017-17593

    Last Modified: 13 Dec 2017

    Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17592

    Last Modified: 13 Dec 2017

    Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17591

    Last Modified: 13 Dec 2017

    Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17590

    Last Modified: 13 Dec 2017

    FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17589

    Last Modified: 13 Dec 2017

    FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17588

    Last Modified: 13 Dec 2017

    FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17587

    Last Modified: 13 Dec 2017

    FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17586

    Last Modified: 13 Dec 2017

    FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17585

    Last Modified: 13 Dec 2017

    FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17584

    Last Modified: 13 Dec 2017

    FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17583

    Last Modified: 13 Dec 2017

    FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17582

    Last Modified: 13 Dec 2017

    FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17581

    Last Modified: 13 Dec 2017

    FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17580

    Last Modified: 13 Dec 2017

    FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17579

    Last Modified: 13 Dec 2017

    FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17578

    Last Modified: 13 Dec 2017

    FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17577

    Last Modified: 13 Dec 2017

    FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17576

    Last Modified: 13 Dec 2017

    FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17575

    Last Modified: 13 Dec 2017

    FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17574

    Last Modified: 13 Dec 2017

    FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17573

    Last Modified: 13 Dec 2017

    FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17572

    Last Modified: 13 Dec 2017

    FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17571

    Last Modified: 13 Dec 2017

    FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    9.8
    Critical

    CVE-2017-17570

    Last Modified: 13 Dec 2017

    FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.

    Source:Ihsan Sencan
    Published:13 Dec 2017
    8.1
    High

    CVE-2017-17562

    Last Modified: 25 Jan 2018

    Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

    Source:Daniel Hodson
    Published:12 Dec 2017
    9.8
    Critical

    CVE-2017-17560

    Last Modified: 18 Dec 2017

    An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.

    Source:Metasploit
    Published:12 Dec 2017
    7.5
    High

    CVE-2017-17538

    Last Modified: 11 Dec 2017

    MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.

    Source:FarazPajohan
    Published:13 Dec 2017