|
266371
|
8.8 |
HIGH
Network
|
readaxo
|
readaxo
|
In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.
|
CWE-352
Origin Validation Error
|
CVE-2016-10757
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266372
|
8.8 |
HIGH
Network
|
kliqqi
|
kliqqi_cms
|
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be u…
|
CWE-352
Origin Validation Error
|
CVE-2016-10756
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266373
|
8.8 |
HIGH
Network
|
abantecart
|
abantecart
|
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pag…
|
CWE-89
SQL Injection
|
CVE-2016-10755
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266374
|
8.8 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
|
CWE-89
SQL Injection
|
CVE-2016-10754
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266375
|
8.8 |
HIGH
Network
|
e107
|
e107
|
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-10753
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266376
|
9.8 |
CRITICAL
Network
|
s9y
|
serendipity
|
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated b…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10752
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266377
|
7.2 |
HIGH
Network
|
osclass
|
osclass
|
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PH…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10751
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266378
|
8.1 |
HIGH
Network
|
hazelcast
|
hazelcast
|
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinReques…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-10750
|
2024-11-21 11:44 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266379
|
6.1 |
MEDIUM
Network
|
tp-link
|
archer_cr700_firmware
|
TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contai…
|
CWE-79
Cross-site Scripting
|
CVE-2016-10719
|
2024-11-21 11:44 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266380
|
9.8 |
CRITICAL
Network
|
cjson_project
|
cjson
|
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10749
|
2024-11-21 11:44 |
2019-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|