|
246211
|
4.9 |
MEDIUM
Network
|
metinfo
|
metinfo
|
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
|
CWE-89
SQL Injection
|
CVE-2018-17129
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246212
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17128
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246213
|
7.5 |
HIGH
Network
|
asus
|
gt-ac5300_firmware
|
blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a ti…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17127
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246214
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
|
CWE-94
Code Injection
|
CVE-2018-17126
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246215
|
7.5 |
HIGH
Network
|
chshcms
|
cscms
|
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
|
CWE-22
Path Traversal
|
CVE-2018-17125
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246216
|
6.1 |
MEDIUM
Network
|
easycms
|
easycms
|
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17113
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246217
|
9.8 |
CRITICAL
Network
|
tecdiary
|
simple_pos
|
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
|
CWE-89
SQL Injection
|
CVE-2018-17110
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246218
|
8.8 |
HIGH
Network
|
sbi
|
sbi_buddy
|
The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-question response during the initial confi…
|
NVD-CWE-noinfo
|
CVE-2018-17108
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246219
|
7.5 |
HIGH
Network
|
tinyftp_project
|
tinyftp
|
In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An attacker can overwrite ebp via a long pathname.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-17106
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246220
|
8.8 |
HIGH
Network
|
microweber
|
microweber
|
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
|
CWE-352
Origin Validation Error
|
CVE-2018-17104
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|