|
247181
|
6.5 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.
|
CWE-352
Origin Validation Error
|
CVE-2018-10248
|
2024-11-21 12:41 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247182
|
5.3 |
MEDIUM
Network
|
awstats
|
awstats
|
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682…
|
CWE-200
Information Exposure
|
CVE-2018-10245
|
2024-11-21 12:41 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247183
|
7.5 |
HIGH
Network
|
ncomputing
|
vspace_pro
|
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulne…
|
CWE-22
Path Traversal
|
CVE-2018-10201
|
2024-11-21 12:41 |
2018-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247184
|
9.8 |
CRITICAL
Network
|
bacnet_protocol_stack_project
|
bacnet_protocol_stack
|
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10238
|
2024-11-21 12:41 |
2018-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247185
|
7.2 |
HIGH
Network
|
poscms
|
poscms
|
POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an attacker can control the value of $data['name'] wi…
|
CWE-94
Code Injection
|
CVE-2018-10236
|
2024-11-21 12:41 |
2018-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247186
|
7.2 |
HIGH
Network
|
poscms
|
poscms
|
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because an attacker can control the value of $cache['setti…
|
CWE-94
Code Injection
|
CVE-2018-10235
|
2024-11-21 12:41 |
2018-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247187
|
6.1 |
MEDIUM
Network
|
zend
|
zend_server
|
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10230
|
2024-11-21 12:41 |
2018-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247188
|
5.4 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10227
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247189
|
9.8 |
CRITICAL
Network
|
thinkphp
|
thinkphp
|
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10225
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247190
|
6.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.
|
CWE-352
Origin Validation Error
|
CVE-2018-10224
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|