CVE-2017-10000
published 2017-08-08CVE-2017-10000: Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that…
PriorityP338high7.7CVSS 3.0
AVNACLPRLUINSCCNINAH
EPSS
1.19%
64.3th percentile
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. While the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Reporting and Analytics. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | hospitality_reporting_and_analytics | — | — |
| oracle | hospitality_reporting_and_analytics | — | — |
| oracle_corporation | hospitality_reporting_and_analytics | — | — |
| oracle_corporation | hospitality_reporting_and_analytics | — | — |
CVSS provenance
nvdv3.07.7HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
exploitdb·2017-12-11
CVE-2017-17628 Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
---
# # # # #
# Exploit Title: Responsive Realestate Script 3.2 - SQL Injection
# Dork: N/A
# Date: 09.12.2017
# Vendor Homepage: https://www.phpscriptsmall.com/
# Software Link: https://www.phpscriptsmall.com/product/responsive-realestate-script/
# Version: 3.2
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: N/A
# # # # #
# Exploit Author: Ihsan Sencan
# Author Web: http://ihsan.net
# Author Social: @ihsansencan
# # # # #
# Description:
# The vulnerability allows an attacker to inject sql commands....
#
# Proof of Concept:
#
# 1)
# http://localhost/[PATH]/property-list?tbud=5001-10000[SQL]&quicksrch1=
#
# 34 columns
#
# Parameter: tbud (GET)
# Type: boolean-based blind
# Title: AND boolean-based blind -
Exploit-DB
Mozilla Firefox < 55 - Denial of Service
exploitdb·2017-10-20·CVSS 7.5
CVE-2017-7783 [HIGH] Mozilla Firefox < 55 - Denial of Service
Mozilla Firefox Firefox Lockout Vulnerability";
//Content to be forcibly viewed
echo "";
//End
echo "setTimeout(\"location.href ='".$location."';\",10000);";
?>
# Solution:
Update to version 55
https://www.mozilla.org/en-US/firefox/55.0/releasenotes/
# Mozilla Foundation Security Advisory:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-18/#CVE-2017-7783
Exploit-DB
Zookeeper 3.5.2 Client - Denial of Service
exploitdb·2017-07-02
CVE-2017-5637 Zookeeper 3.5.2 Client - Denial of Service
Zookeeper 3.5.2 Client - Denial of Service
---
#!/usr/bin/python
# Exploit Title: Zookeeper Client Denial Of Service (Port 2181)
# Date: 2/7/2017
# Exploit Author: Brandon Dennis
# Email: [email protected]
# Software Link: http://zookeeper.apache.org/releases.html#download
# Zookeeper Version: 3.5.2
# Tested on: Windows 2008 R2, Windows 2012 R2 x64 & x86
# Description: The wchp command to the ZK port 2181 will gather open internal files by each session/watcher and organize them for the requesting client.
# This command is CPU intensive and will cause a denial of service to the port as well as spike the CPU of the remote machine to 90-100% consistently before any other traffic.
# The average amount of threads uses was 10000 for testing. This should work on all 3.x+ versions of Zook
2017-08-08
Published