Security Vulnerabilities
- CVEs Published In September 2017
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75.
SQL injection vulnerability in Pragyan CMS 3.0.
Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication, and perform other unspecified actions.
Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.
SQL injection vulnerability in Concrete5 5.7.3.1.
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.