Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2017
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
CVSS Score
5.3
EPSS Score
0.002
Published
2017-12-20
Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.
CVSS Score
9.8
EPSS Score
0.007
Published
2017-12-20
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
CVSS Score
4.8
EPSS Score
0.002
Published
2017-12-20
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-12-20
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-12-20
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.
CVSS Score
7.5
EPSS Score
0.007
Published
2017-12-19
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.
CVSS Score
9.8
EPSS Score
0.045
Published
2017-12-19
A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-12-19
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-12-19
Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-12-19


Contact Us

Shodan ® - All rights reserved