|
246261
|
6.1 |
MEDIUM
Network
|
seacms
|
seacms
|
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14517
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246262
|
9.8 |
CRITICAL
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter.
|
CWE-89
SQL Injection
|
CVE-2018-14515
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246263
|
9.8 |
CRITICAL
Network
|
icmsdev
|
icms
|
An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-14514
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246264
|
6.1 |
MEDIUM
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the index.php?m=…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14513
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246265
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14512
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246266
|
8.8 |
HIGH
Network
|
mitmproxy
|
mitmproxy
|
mitmweb in mitmproxy v4.0.3 allows DNS Rebinding attacks, related to tools/web/app.py.
|
CWE-20
Improper Input Validation
|
CVE-2018-14505
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246267
|
9.8 |
CRITICAL
Network
|
joyplus_project
|
joyplus-cms
|
manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.
|
CWE-89
SQL Injection
|
CVE-2018-14501
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246268
|
6.1 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14500
|
2024-11-21 12:49 |
2018-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246269
|
7.5 |
HIGH
Network
|
tendacn
|
ac7_firmware ac9_firmware ac10_firmware ac15_firmware ac18_firmware
|
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14492
|
2024-11-21 12:49 |
2018-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246270
|
6.1 |
MEDIUM
Network
|
goodoldweb
|
orange_forum
|
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
|
CWE-601
Open Redirect
|
CVE-2018-14474
|
2024-11-21 12:49 |
2018-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|