|
247141
|
7.2 |
HIGH
Network
|
jspxcms
|
jspxcms
|
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
|
CWE-284
Improper Access Control
|
CVE-2018-16553
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247142
|
4.7 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16514
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247143
|
4.3 |
MEDIUM
Network
|
creatiwity
|
witycms
|
A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input parameters are filtered, e.g., the /admin/user/users Nickname, email, firstname, …
|
CWE-89
SQL Injection
|
CVE-2018-16251
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247144
|
5.4 |
MEDIUM
Network
|
creatiwity
|
witycms
|
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name" parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16250
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247145
|
4.8 |
MEDIUM
Network
|
b3log
|
symphony
|
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16249
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247146
|
8.0 |
HIGH
Adjacent
|
yealink
|
ultra-elegant_ip_phone_sip-t41p_firmware
|
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated rem…
|
CWE-22
Path Traversal
|
CVE-2018-16221
|
2024-11-21 12:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247147
|
8.8 |
HIGH
Network
|
yealink
|
ultra-elegant_ip_phone_sip-t41p_firmware
|
A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execution or settings mod…
|
CWE-352
Origin Validation Error
|
CVE-2018-16218
|
2024-11-21 12:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247148
|
8.8 |
HIGH
Network
|
yealink
|
ultra-elegant_ip_phone_sip-t41p_firmware
|
The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker to trigger OS commands or open a reverse shell via …
|
CWE-78
OS Command
|
CVE-2018-16217
|
2024-11-21 12:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247149
|
7.8 |
HIGH
Local
|
fujitsu
|
paperstream_ip_\(twain\)
|
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One o…
|
CWE-426
Untrusted Search Path
|
CVE-2018-16156
|
2024-11-21 12:52 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247150
|
4.8 |
MEDIUM
Network
|
ipbrick
|
ipbrick_os
|
An issue was discovered in the administration page in IPBRICK OS 6.3. There are multiple XSS vulnerabilities.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16138
|
2024-11-21 12:52 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|