|
247391
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
|
CWE-22
Path Traversal
|
CVE-2018-15695
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247392
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code executio…
|
CWE-22
Path Traversal
|
CVE-2018-15694
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247393
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15899
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247394
|
7.5 |
HIGH
Network
|
icmsdev
|
icms
|
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP ad…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-15895
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247395
|
9.8 |
CRITICAL
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter.
|
CWE-89
SQL Injection
|
CVE-2018-15894
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247396
|
9.8 |
CRITICAL
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter.
|
CWE-89
SQL Injection
|
CVE-2018-15893
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247397
|
9.8 |
CRITICAL
Network
|
aspcms
|
aspcms
|
An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp page, they can be registered with the super administrators GroupID directly.
|
CWE-20
Improper Input Validation
|
CVE-2018-15888
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247398
|
7.5 |
HIGH
Network
|
ovation
|
findme
|
Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities o…
|
CWE-20
Improper Input Validation
|
CVE-2018-15885
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247399
|
6.1 |
MEDIUM
Network
|
zyxel
|
vmg3312_b10b_firmware
|
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15602
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247400
|
4.3 |
MEDIUM
Network
|
vanillaforums
|
vanilla_forums
|
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-15833
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|