|
246881
|
9.8 |
CRITICAL
Network
|
thinkphp
|
thinkphp
|
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
|
CWE-89
SQL Injection
|
CVE-2018-16385
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246882
|
7.5 |
HIGH
Network
|
owasp
|
owasp_modsecurity_core_rule_set
|
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the …
|
CWE-89
SQL Injection
|
CVE-2018-16384
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246883
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16382
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246884
|
8.8 |
HIGH
Network
|
digimute
|
ogma_cms
|
An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2018-16380
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246885
|
4.8 |
MEDIUM
Network
|
digimute
|
ogma_cms
|
Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16379
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246886
|
8.8 |
HIGH
Network
|
uclouvain
|
openjpeg
|
An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16376
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246887
|
8.8 |
HIGH
Network
|
uclouvain
|
openjpeg
|
An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16375
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246888
|
4.8 |
MEDIUM
Network
|
frog_cms_project
|
frog_cms
|
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16374
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246889
|
4.9 |
MEDIUM
Network
|
frog_cms_project
|
frog_cms
|
Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16373
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246890
|
6.1 |
MEDIUM
Network
|
ideacms
|
ideacms
|
The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16372
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|