|
248011
|
7.2 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
|
CWE-89
SQL Injection
|
CVE-2018-10050
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248012
|
4.8 |
MEDIUM
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10049
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248013
|
8.8 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
|
CWE-352
Origin Validation Error
|
CVE-2018-10048
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248014
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10033
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248015
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10032
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248016
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-10031
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248017
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-10030
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248018
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10029
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248019
|
5.3 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
|
CWE-200
Information Exposure
|
CVE-2018-10028
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248020
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10026
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|