|
247431
|
8.8 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-16366
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247432
|
8.8 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-16365
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247433
|
6.1 |
MEDIUM
Network
|
mantisbt
|
source_integration
|
An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site scripting (XSS) vulnerability in the Manage Repository and Changesets List pages …
|
CWE-79
Cross-site Scripting
|
CVE-2018-16362
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247434
|
6.8 |
MEDIUM
Network
|
google
|
gvisor
|
Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.
|
NVD-CWE-noinfo
|
CVE-2018-16359
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247435
|
5.4 |
MEDIUM
Network
|
dotclear
|
dotclear
|
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS pay…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16358
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247436
|
9.8 |
CRITICAL
Network
|
fhcrm_project
|
fhcrm
|
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter.
|
CWE-89
SQL Injection
|
CVE-2018-16354
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247437
|
9.8 |
CRITICAL
Network
|
fhcrm_project
|
fhcrm
|
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter.
|
CWE-89
SQL Injection
|
CVE-2018-16353
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247438
|
9.8 |
CRITICAL
Network
|
weaselcms_project
|
weaselcms
|
There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16352
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247439
|
6.1 |
MEDIUM
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16350
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247440
|
6.1 |
MEDIUM
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16349
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|