|
246601
|
9.8 |
CRITICAL
Network
|
swa
|
swa.jacad
|
SWA SWA.JACAD 3.1.37 Build 024 has SQL Injection via the /academico/aluno/esqueci-minha-senha/ studentId parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17575
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246602
|
5.4 |
MEDIUM
Network
|
ymfe
|
yapi
|
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17574
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246603
|
9.8 |
CRITICAL
Network
|
smartlogix
|
wp-insert
|
The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-17573
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246604
|
6.1 |
MEDIUM
Network
|
vanillaforums
|
vanilla
|
Vanilla before 2.6.1 allows XSS via the email field of a profile.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17571
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246605
|
7.5 |
HIGH
Network
|
jekyllrb
|
jekyll
|
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
|
CWE-59
Link Following
|
CVE-2018-17567
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246606
|
9.8 |
CRITICAL
Network
|
multiplanet
|
alphaindex_dictionaries
|
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17397
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246607
|
9.8 |
CRITICAL
Network
|
osthemeclub
|
timetable_schedule
|
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17394
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246608
|
9.8 |
CRITICAL
Network
|
super_cms_blog_pro_project
|
super_cms_blog_pro
|
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17391
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246609
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
social_factory
|
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17385
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246610
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
swap_factory
|
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17384
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|