|
246441
|
8.8 |
HIGH
Network
|
sophos
|
sfos
|
SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parame…
|
CWE-89
SQL Injection
|
CVE-2018-16116
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246442
|
6.1 |
MEDIUM
Network
|
b3log
|
solo
|
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts …
|
CWE-79
Cross-site Scripting
|
CVE-2018-16248
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246443
|
5.4 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16247
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246444
|
7.2 |
HIGH
Network
|
tp-link
|
tl-wr1043nd_firmware
|
Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerF…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16119
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246445
|
7.2 |
HIGH
Network
|
jspxcms
|
jspxcms
|
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
|
CWE-284
Improper Access Control
|
CVE-2018-16553
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246446
|
4.7 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16514
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246447
|
4.3 |
MEDIUM
Network
|
creatiwity
|
witycms
|
A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input parameters are filtered, e.g., the /admin/user/users Nickname, email, firstname, …
|
CWE-89
SQL Injection
|
CVE-2018-16251
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246448
|
5.4 |
MEDIUM
Network
|
creatiwity
|
witycms
|
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name" parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16250
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246449
|
4.8 |
MEDIUM
Network
|
b3log
|
symphony
|
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16249
|
2024-11-21 12:52 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246450
|
8.0 |
HIGH
Adjacent
|
yealink
|
ultra-elegant_ip_phone_sip-t41p_firmware
|
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated rem…
|
CWE-22
Path Traversal
|
CVE-2018-16221
|
2024-11-21 12:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|