CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102495 | CVE-2017-5675 | Candidate | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models. The mail-sending form in the mail.htm page allows an attacker to inject a command into the receiver1 field in the form; it will be executed with root privileges. | Assigned (20170131) | None (candidate not yet proposed) | View | |
102494 | CVE-2017-5674 | Candidate | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1 " - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password. | Assigned (20170131) | None (candidate not yet proposed) | View | |
102493 | CVE-2017-5673 | Candidate | In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, crypsis/layouts/message/item/bottom/default.php, crypsisb3/layouts/message/item/default.php, crypsisb3/layouts/message/item/top/default.php, and crypsisb3/layouts/message/item/bottom/default.php. This is fixed in 5.0.5. | Assigned (20170131) | None (candidate not yet proposed) | View | |
102492 | CVE-2017-5672 | Candidate | Kony Enterprise Mobile Management (EMM) before 4.2.5.2 has the vulnerability of disclosing the private key in clear-text when changing the parameters of the request. | Assigned (20170131) | None (candidate not yet proposed) | View | |
102491 | CVE-2017-5671 | Candidate | Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file. | Assigned (20170131) | None (candidate not yet proposed) | View |
Page 445 of 20943, showing 5 records out of 104715 total, starting on record 2221, ending on 2225