|
247961
|
5.4 |
MEDIUM
Network
|
discuz
|
discuzx
|
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10297
|
2024-11-21 12:41 |
2018-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247962
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10296
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247963
|
8.8 |
HIGH
Network
|
chemcms_project
|
chemcms
|
ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-10295
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247964
|
8.8 |
HIGH
Network
|
ericssonlg
|
ipecs_nms
|
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certa…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-10286
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247965
|
9.8 |
CRITICAL
Network
|
ericssonlg
|
ipecs_nms
|
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10285
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247966
|
5.5 |
MEDIUM
Local
|
artifex debian
|
mupdf debian_linux
|
In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pd…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-10289
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247967
|
5.4 |
MEDIUM
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10268
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247968
|
8.8 |
HIGH
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10267
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247969
|
8.8 |
HIGH
Network
|
beescms
|
beescms
|
BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10266
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247970
|
8.8 |
HIGH
Network
|
hongcms_project
|
hongcms
|
An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10265
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|