|
247471
|
7.8 |
HIGH
Local
|
mc1soft
|
zip-n-go
|
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16302
|
2024-11-21 12:52 |
2018-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247472
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16298
|
2024-11-21 12:52 |
2018-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247473
|
9.8 |
CRITICAL
Network
|
phpkaiyuancms
|
phpopensourcecms
|
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir par…
|
CWE-89
SQL Injection
|
CVE-2018-16278
|
2024-11-21 12:52 |
2018-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247474
|
7.8 |
HIGH
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16276
|
2024-11-21 12:52 |
2018-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247475
|
7.8 |
HIGH
Local
|
opswat
|
metadefender
|
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-16275
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247476
|
9.8 |
CRITICAL
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2018-16239
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247477
|
7.2 |
HIGH
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl…
|
CWE-20
Improper Input Validation
|
CVE-2018-16238
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247478
|
2.7 |
LOW
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
|
CWE-22
Path Traversal
|
CVE-2018-16237
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247479
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16236
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247480
|
6.1 |
MEDIUM
Network
|
morningstarsecurity
|
whatweb
|
MorningStar WhatWeb 0.4.9 has XSS via JSON report files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16234
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|