|
247631
|
9.8 |
CRITICAL
Network
|
thinkphp
|
thinkphp
|
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
|
CWE-89
SQL Injection
|
CVE-2018-10225
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247632
|
6.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.
|
CWE-352
Origin Validation Error
|
CVE-2018-10224
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247633
|
6.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.
|
CWE-352
Origin Validation Error
|
CVE-2018-10223
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247634
|
8.8 |
HIGH
Network
|
icmsdev
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.
|
CWE-352
Origin Validation Error
|
CVE-2018-10222
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247635
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuz…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10221
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247636
|
8.8 |
HIGH
Network
|
mushmush
|
glastopf
|
Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/ha…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-10220
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247637
|
5.3 |
MEDIUM
Network
|
baijiacms_project
|
baijiacms
|
baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request.
|
CWE-200
Information Exposure
|
CVE-2018-10219
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247638
|
5.3 |
MEDIUM
Network
|
hyper
|
hyperstart
|
hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to runV 1.0.0 for Docker.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10205
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247639
|
9.8 |
CRITICAL
Network
|
mruby
|
mruby
|
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to ex…
|
CWE-416
Use After Free
|
CVE-2018-10199
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247640
|
8.8 |
HIGH
Network
|
purevpn
|
purevpn
|
PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN protocol, the "sevpnclient" service executes "openv…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10204
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|