WAFPlanet

CVE Database - 2017

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

4807
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2017-18004

MEDIUM
5.40 CVSS 3.0

Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.

Cross-Site Scripting (XSS)
WAF: High

CVE-2016-10704

MEDIUM
6.10 CVSS 3.1

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17089

MEDIUM
4.80 CVSS 3.0

custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-12813

MEDIUM
6.10 CVSS 3.0

PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-12812

MEDIUM
6.10 CVSS 3.0

PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-12811

MEDIUM
6.10 CVSS 3.0

PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-12810

MEDIUM
6.10 CVSS 3.0

PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17995

MEDIUM
5.40 CVSS 3.0

Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17994

MEDIUM
5.40 CVSS 3.0

Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17993

MEDIUM
5.40 CVSS 3.0

Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17992

CRITICAL
9.80 CVSS 3.0

Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name parameter in a download_form action.

Path Traversal
WAF: High

CVE-2017-17991

MEDIUM
5.40 CVSS 3.0

Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17990

HIGH
8.80 CVSS 3.0

Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2017-17989

MEDIUM
5.40 CVSS 3.0

Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17988

MEDIUM
4.80 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17987

HIGH
7.20 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php.

Unrestricted File Upload
WAF: Medium

CVE-2017-17986

MEDIUM
4.80 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17985

MEDIUM
4.80 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17984

MEDIUM
4.80 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17983

HIGH
8.80 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter.

SQL Injection
WAF: High

CVE-2017-17982

MEDIUM
6.80 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2017-17981

MEDIUM
5.40 CVSS 3.0

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17901

HIGH
7.50 CVSS 3.0

ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2014-9515

CRITICAL
9.80 CVSS 3.0

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

Insecure Deserialization
WAF: Medium

CVE-2014-8119

HIGH
7.50 CVSS 3.0

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

Improper Input Validation
WAF: Medium

CVE-2014-3630

CRITICAL
9.80 CVSS 3.0

XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.

XML External Entity (XXE)
WAF: High

CVE-2014-0121

CRITICAL
9.80 CVSS 3.0

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

Improper Authentication
WAF: Low

CVE-2014-0120

HIGH
8.80 CVSS 3.0

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2017-17971

MEDIUM
6.10 CVSS 3.0

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17933

MEDIUM
6.10 CVSS 3.1

cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17920

HIGH
8.10 CVSS 3.0

SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

SQL Injection
WAF: High

CVE-2017-17919

HIGH
8.10 CVSS 3.0

SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

SQL Injection
WAF: High

CVE-2017-17917

HIGH
8.10 CVSS 3.1

SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

SQL Injection
WAF: High

CVE-2017-17916

HIGH
8.10 CVSS 3.1

SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

SQL Injection
WAF: High

CVE-2017-16876

MEDIUM
6.10 CVSS 3.0

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-3651

HIGH
7.50 CVSS 3.0

JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2014-4914

CRITICAL
9.80 CVSS 3.0

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

SQL Injection
WAF: High

CVE-2017-17967

MEDIUM
5.50 CVSS 3.0

pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.

Improper Input Validation
WAF: Medium

CVE-2017-17960

HIGH
8.80 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2017-17959

CRITICAL
9.80 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.

SQL Injection
WAF: High

CVE-2017-17958

MEDIUM
6.10 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17957

CRITICAL
9.80 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.

SQL Injection
WAF: High

CVE-2017-17956

MEDIUM
6.10 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17955

MEDIUM
6.10 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17954

MEDIUM
6.10 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17953

MEDIUM
6.10 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2017-17952

HIGH
8.60 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.

Improper Input Validation
WAF: Medium

CVE-2017-17951

CRITICAL
9.80 CVSS 3.0

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.

SQL Injection
WAF: High

CVE-2017-17950

HIGH
8.80 CVSS 3.0

Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.

SQL Injection
WAF: High

CVE-2017-17949

MEDIUM
6.10 CVSS 3.0

Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.

Cross-Site Scripting (XSS)
WAF: High
Page 1 of 97 (4807 CVEs)