|
247761
|
9.1 |
CRITICAL
Network
|
phoenixcontact
|
fl_switch_3005_firmware fl_switch_3005t_firmware fl_switch_3004t-fx_firmware fl_switch_3004t-fx_st_firmware fl_switch_3008_firmware fl_switch_3008t_firmware fl_switch_3006t-2fx_firm…
|
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.
|
CWE-78
OS Command
|
CVE-2018-10730
|
2024-11-21 12:41 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247762
|
5.3 |
MEDIUM
Network
|
phoenixcontact
|
fl_switch_3005_firmware fl_switch_3005t_firmware fl_switch_3004t-fx_firmware fl_switch_3004t-fx_st_firmware fl_switch_3008_firmware fl_switch_3008t_firmware fl_switch_3006t-2fx_firm…
|
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user.
|
CWE-200
Information Exposure
|
CVE-2018-10729
|
2024-11-21 12:41 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247763
|
8.1 |
HIGH
Network
|
phoenixcontact
|
fl_switch_3005_firmware fl_switch_3005t_firmware fl_switch_3004t-fx_firmware fl_switch_3004t-fx_st_firmware fl_switch_3008_firmware fl_switch_3008t_firmware fl_switch_3006t-2fx_firm…
|
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10728
|
2024-11-21 12:41 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247764
|
8.8 |
HIGH
Network
|
projectpier
|
projectpier
|
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable exten…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-10760
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247765
|
9.8 |
CRITICAL
Network
|
projectpier
|
projectpier
|
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10759
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247766
|
6.5 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10241
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247767
|
7.3 |
HIGH
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. Th…
|
CWE-331
Insufficient Entropy
|
CVE-2018-10240
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247768
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10738
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247769
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10737
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247770
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10736
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|