|
247171
|
5.4 |
MEDIUM
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10268
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247172
|
8.8 |
HIGH
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10267
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247173
|
8.8 |
HIGH
Network
|
beescms
|
beescms
|
BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10266
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247174
|
8.8 |
HIGH
Network
|
hongcms_project
|
hongcms
|
An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10265
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247175
|
9.8 |
CRITICAL
Network
|
adaltech
|
g-ticket
|
Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10284
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247176
|
9.8 |
CRITICAL
Network
|
cliquemania
|
loja_virtual
|
CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.
|
CWE-89
SQL Injection
|
CVE-2018-10283
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247177
|
7.8 |
HIGH
Local
|
nasm
|
netwide_assembler
|
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10254
|
2024-11-21 12:41 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247178
|
7.5 |
HIGH
Network
|
paessler
|
prtg_network_monitor
|
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10253
|
2024-11-21 12:41 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247179
|
8.8 |
HIGH
Network
|
baijiacms_project
|
baijiacms
|
baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-10249
|
2024-11-21 12:41 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247180
|
5.4 |
MEDIUM
Network
|
icmsdev
|
icms
|
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10250
|
2024-11-21 12:41 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|