|
246201
|
7.8 |
HIGH
Local
|
deltaww
|
tpeditor
|
In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user inp…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17927
|
2024-11-21 12:55 |
2018-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246202
|
9.8 |
CRITICAL
Network
|
bagesoft
|
bagecms
|
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= …
|
CWE-94
Code Injection
|
CVE-2018-18258
|
2024-11-21 12:55 |
2018-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246203
|
7.5 |
HIGH
Network
|
bagesoft
|
bagecms
|
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/te…
|
CWE-22
Path Traversal
|
CVE-2018-18257
|
2024-11-21 12:55 |
2018-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246204
|
8.8 |
HIGH
Network
|
youke365
|
youke_365
|
In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
|
CWE-352
Origin Validation Error
|
CVE-2018-18215
|
2024-11-21 12:55 |
2018-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246205
|
9.8 |
CRITICAL
Network
|
youke365
|
youke_365
|
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.
|
CWE-89
SQL Injection
|
CVE-2018-18242
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246206
|
9.8 |
CRITICAL
Network
|
pippo
|
pippo
|
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unma…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-18240
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246207
|
6.1 |
MEDIUM
Network
|
tecrail
|
responsive_filemanager
|
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18062
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246208
|
7.5 |
HIGH
Network
|
tecrail
|
responsive_filemanager
|
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.
|
CWE-287
Improper Authentication
|
CVE-2018-18061
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246209
|
8.1 |
HIGH
Network
|
pbootcms
|
pbootcms
|
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
|
CWE-89
SQL Injection
|
CVE-2018-18211
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246210
|
6.1 |
MEDIUM
Network
|
dilicms
|
dilicms
|
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18210
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|