|
247671
|
6.1 |
MEDIUM
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
|
CWE-79
Cross-site Scripting
|
CVE-2018-11472
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247672
|
5.4 |
MEDIUM
Network
|
getcockpit
|
cockpit
|
Cockpit 0.5.5 has XSS via a collection, form, or region.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11471
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247673
|
8.8 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
|
CWE-89
SQL Injection
|
CVE-2018-11470
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247674
|
5.9 |
MEDIUM
Network
|
haproxy canonical
|
haproxy ubuntu_linux
|
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticate…
|
CWE-200
Information Exposure
|
CVE-2018-11469
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247675
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by m…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11468
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247676
|
8.8 |
HIGH
Network
|
easyservice_billing_project
|
easyservice_billing
|
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.
|
CWE-352
Origin Validation Error
|
CVE-2018-11445
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247677
|
9.8 |
CRITICAL
Network
|
easyservice_billing_project
|
easyservice_billing
|
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
|
CWE-89
SQL Injection
|
CVE-2018-11444
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247678
|
6.1 |
MEDIUM
Network
|
easyservice_billing_project
|
easyservice_billing
|
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11443
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247679
|
8.8 |
HIGH
Network
|
easyservice_billing_project
|
easyservice_billing
|
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.
|
CWE-352
Origin Validation Error
|
CVE-2018-11442
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247680
|
8.8 |
HIGH
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11440
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|