diff --git a/cves/2013/CVE-2013-2251.yaml b/cves/2013/CVE-2013-2251.yaml index bef95ecb02..ba88f6aa5f 100644 --- a/cves/2013/CVE-2013-2251.yaml +++ b/cves/2013/CVE-2013-2251.yaml @@ -2,7 +2,7 @@ id: CVE-2013-2251 info: name: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution - author: exploitation & @dwisiswant0 + author: exploitation,dwisiswant0 severity: critical description: In Struts 2 before 2.3.15.1 the information following "action:", "redirect:" or "redirectAction:" is not properly sanitized. Since said information will be evaluated as OGNL expression against the value stack, this introduces the possibility to inject server side code. reference: http://struts.apache.org/release/2.3.x/docs/s2-016.html diff --git a/cves/2017/CVE-2017-14849.yaml b/cves/2017/CVE-2017-14849.yaml index 01b36cd82b..a6fe2a3244 100644 --- a/cves/2017/CVE-2017-14849.yaml +++ b/cves/2017/CVE-2017-14849.yaml @@ -2,7 +2,7 @@ id: CVE-2017-14849 info: name: Node.js 8.5.0 >=< 8.6.0 Directory Traversal - author: Random-Robbie + author: Random_Robbie severity: high description: Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules. tags: cve,cve2017,nodejs,lfi diff --git a/cves/2017/CVE-2017-5638.yaml b/cves/2017/CVE-2017-5638.yaml index 43a75f32f6..5d477c119a 100644 --- a/cves/2017/CVE-2017-5638.yaml +++ b/cves/2017/CVE-2017-5638.yaml @@ -1,6 +1,6 @@ id: CVE-2017-5638 info: - author: Random Robbie + author: Random_Robbie name: Apache Struts2 RCE severity: critical description: Struts is vulnerable to remote command injection attacks through incorrectly parsing an attacker’s invalid Content-Type HTTP header. The Struts vulnerability allows these commands to be executed under the privileges of the Web server. diff --git a/cves/2017/CVE-2017-7269.yaml b/cves/2017/CVE-2017-7269.yaml index 72e59465d5..82e8e080d4 100644 --- a/cves/2017/CVE-2017-7269.yaml +++ b/cves/2017/CVE-2017-7269.yaml @@ -2,7 +2,7 @@ id: CVE-2017-7269 info: name: Windows Server 2003 & IIS 6.0 RCE - author: thomas_from_offensity & @geeknik + author: thomas_from_offensity,geeknik severity: critical description: Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If