|
246091
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c307_firmware
|
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWiza…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17313
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246092
|
6.1 |
MEDIUM
Network
|
ricoh
|
aficio_mp_301spf_firmware
|
On the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUs…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17312
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246093
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c6503_firmware
|
On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUs…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17311
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246094
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c1803_jpn_firmware
|
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUse…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17310
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246095
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c406zspf_firmware
|
On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWiz…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17309
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246096
|
9.8 |
CRITICAL
Network
|
thinkphp
|
thinkphp
|
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
|
CWE-89
SQL Injection
|
CVE-2018-17566
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246097
|
9.8 |
CRITICAL
Network
|
horus_cms_project
|
horus_cms
|
Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI.
|
CWE-89
SQL Injection
|
CVE-2018-17410
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246098
|
7.5 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
|
CWE-22
Path Traversal
|
CVE-2018-17365
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246099
|
8.1 |
HIGH
Network
|
postman
|
postman
|
An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-17215
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246100
|
5.4 |
MEDIUM
Network
|
modx
|
modx_revolution
|
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17556
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|