|
246201
|
5.4 |
MEDIUM
Network
|
vms-studio
|
quizlord
|
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17140
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246202
|
8.8 |
HIGH
Network
|
ultimatefosters
|
ultimatepos
|
UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-17139
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246203
|
5.4 |
MEDIUM
Network
|
nickelpro
|
jibu_pro
|
The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17138
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246204
|
9.8 |
CRITICAL
Network
|
prezi
|
next
|
Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions.
|
NVD-CWE-noinfo
|
CVE-2018-17137
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246205
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
|
CWE-89
SQL Injection
|
CVE-2018-17136
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246206
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.
|
CWE-94
Code Injection
|
CVE-2018-17134
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246207
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
|
CWE-94
Code Injection
|
CVE-2018-17133
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246208
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
|
CWE-94
Code Injection
|
CVE-2018-17132
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246209
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
|
CWE-94
Code Injection
|
CVE-2018-17131
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246210
|
5.4 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
|
CWE-79
Cross-site Scripting
|
CVE-2018-17130
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|