|
248101
|
9.8 |
CRITICAL
Network
|
projectpier
|
projectpier
|
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10759
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248102
|
6.5 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10241
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248103
|
7.3 |
HIGH
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. Th…
|
CWE-331
Insufficient Entropy
|
CVE-2018-10240
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248104
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10738
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248105
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10737
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248106
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10736
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248107
|
7.2 |
HIGH
Network
|
nagios
|
nagios_xi
|
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10735
|
2024-11-21 12:41 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248108
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf foxit_reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the ta…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-10495
|
2024-11-21 12:41 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248109
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf foxit_reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the tar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10494
|
2024-11-21 12:41 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248110
|
6.5 |
MEDIUM
Network
|
foxitsoftware
|
phantompdf foxit_reader
|
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10493
|
2024-11-21 12:41 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|