|
247221
|
8.8 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
|
CWE-352
Origin Validation Error
|
CVE-2018-10048
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247222
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10033
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247223
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10032
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247224
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-10031
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247225
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-10030
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247226
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10029
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247227
|
5.3 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
|
CWE-200
Information Exposure
|
CVE-2018-10028
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247228
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10026
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247229
|
9.8 |
CRITICAL
Network
|
ubiquoss
|
vp5208a_firmware
|
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credential…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-10024
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247230
|
5.4 |
MEDIUM
Network
|
catfish-cms
|
catfish_cms
|
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
|
CWE-79
Cross-site Scripting
|
CVE-2018-10023
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|