|
265831
|
6.5 |
MEDIUM
Adjacent
|
logitech
|
k400r_firmware k360_firmware k750_firmware k830_firmware unifying_receiver_firmware
|
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
|
CWE-74
Injection
|
CVE-2016-10761
|
2024-11-21 11:44 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265832
|
9.8 |
CRITICAL
Network
|
seowonintech
|
swr-300a_firmware swr-300b_firmware swr-300c_firmware swr-300bg_firmware
|
On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.
|
CWE-77
Command Injection
|
CVE-2016-10760
|
2024-11-21 11:44 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265833
|
9.8 |
CRITICAL
Network
|
precurio
|
precurio
|
The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used t…
|
CWE-22
Path Traversal
|
CVE-2016-10759
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265834
|
8.8 |
HIGH
Network
|
phpkit
|
phpkit
|
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10758
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265835
|
8.8 |
HIGH
Network
|
readaxo
|
readaxo
|
In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.
|
CWE-352
Origin Validation Error
|
CVE-2016-10757
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265836
|
8.8 |
HIGH
Network
|
kliqqi
|
kliqqi_cms
|
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be u…
|
CWE-352
Origin Validation Error
|
CVE-2016-10756
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265837
|
8.8 |
HIGH
Network
|
abantecart
|
abantecart
|
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pag…
|
CWE-89
SQL Injection
|
CVE-2016-10755
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265838
|
8.8 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
|
CWE-89
SQL Injection
|
CVE-2016-10754
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265839
|
8.8 |
HIGH
Network
|
e107
|
e107
|
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-10753
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265840
|
9.8 |
CRITICAL
Network
|
s9y
|
serendipity
|
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated b…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-10752
|
2024-11-21 11:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|