Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-25 CVE-2017-8115 Path Traversal vulnerability in Modx Revolution 2.5.7
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
network
low complexity
modx CWE-22
5.3
2017-04-25 CVE-2017-8057 Information Exposure vulnerability in Joomla Joomla!
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
network
low complexity
joomla CWE-200
5.3
2017-04-25 CVE-2017-7989 Unrestricted Upload of File with Dangerous Type vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
network
low complexity
joomla CWE-434
6.5
2017-04-25 CVE-2017-7988 Unspecified vulnerability in Joomla Joomla!
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
network
low complexity
joomla
5.3
2017-04-25 CVE-2017-7987 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7986 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7985 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7984 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7983 Information Exposure vulnerability in Joomla Joomla!
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
network
low complexity
joomla CWE-200
5.3
2017-04-25 CVE-2017-5625 NULL Pointer Dereference vulnerability in Oneplus Oxygenos 3.2.8/3.5.4/4.0.2
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.
low complexity
oneplus CWE-476
4.6