|
246891
|
6.1 |
MEDIUM
Network
|
nagios
|
fusion
|
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12501
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246892
|
9.8 |
CRITICAL
Network
|
icmsdev
|
icms
|
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
|
CWE-89
SQL Injection
|
CVE-2018-12498
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246893
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12495
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246894
|
6.5 |
MEDIUM
Network
|
publiccms
|
publiccms
|
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.
|
CWE-22
Path Traversal
|
CVE-2018-12494
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246895
|
6.5 |
MEDIUM
Network
|
publiccms
|
publiccms
|
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/list.html?path=../ URI.
|
CWE-22
Path Traversal
|
CVE-2018-12493
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246896
|
7.5 |
HIGH
Network
|
phpok
|
phpok
|
PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.
|
CWE-20
Improper Input Validation
|
CVE-2018-12492
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246897
|
9.8 |
CRITICAL
Network
|
phpok
|
phpok
|
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-12491
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246898
|
9.8 |
CRITICAL
Network
|
the_olive_tree_ftp_server_project
|
the_olive_tree_ftp_server
|
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboa…
|
CWE-200
Information Exposure
|
CVE-2018-12481
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246899
|
9.8 |
CRITICAL
Network
|
gnome
|
evolution
|
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12422
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246900
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
libavcodec in FFmpeg 4.0 may trigger a NULL pointer dereference if the studio profile is incorrectly detected while converting a crafted AVI file to MPEG4, leading to a denial of service, related to …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-12460
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|