|
247801
|
5.4 |
MEDIUM
Network
|
website_seller_script_project
|
website_seller_script
|
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15896
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247802
|
8.8 |
HIGH
Network
|
e107
|
e107
|
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
|
CWE-352
Origin Validation Error
|
CVE-2018-15901
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247803
|
8.8 |
HIGH
Network
|
ricoh
|
mp_c4504ex_firmware
|
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-15884
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247804
|
9.8 |
CRITICAL
Network
|
sapplica
|
sentrifugo
|
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
|
CWE-89
SQL Injection
|
CVE-2018-15873
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247805
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_admanager_plus
|
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15740
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247806
|
6.1 |
MEDIUM
Network
|
manageengine
|
admanager_plus
|
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15608
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247807
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. …
|
CWE-79
Cross-site Scripting
|
CVE-2018-15596
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247808
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615_firmware
|
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15839
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247809
|
8.6 |
HIGH
Local
|
export_users_to_csv_project
|
export_users_to_csv
|
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-15571
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247810
|
8.8 |
HIGH
Network
|
mutiny
|
mutiny
|
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands wi…
|
CWE-78
OS Command
|
CVE-2018-15529
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|