|
247461
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16325
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247462
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16324
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247463
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into…
|
CWE-200
Information Exposure
|
CVE-2018-16323
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247464
|
7.2 |
HIGH
Network
|
idreamsoft
|
icms
|
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
|
CWE-22
Path Traversal
|
CVE-2018-16320
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247465
|
5.4 |
MEDIUM
Network
|
portainer
|
portainer
|
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16316
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247466
|
6.5 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
|
CWE-352
Origin Validation Error
|
CVE-2018-16315
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247467
|
8.8 |
HIGH
Network
|
icmsdev
|
icms
|
An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.p…
|
CWE-352
Origin Validation Error
|
CVE-2018-16314
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247468
|
6.1 |
MEDIUM
Network
|
bludit
|
bludit
|
Bludit 2.3.4 allows XSS via a user name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16313
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247469
|
8.6 |
HIGH
Local
|
ninjaforms
|
ninja_forms
|
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-16308
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247470
|
7.5 |
HIGH
Network
|
tracker-software
|
pdf-xchange_editor
|
PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a related issue to CVE-2003-1564.
|
CWE-611
XXE
|
CVE-2018-16303
|
2024-11-21 12:52 |
2018-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|