|
246361
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17128
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246362
|
7.5 |
HIGH
Network
|
asus
|
gt-ac5300_firmware
|
blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a ti…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17127
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246363
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
|
CWE-94
Code Injection
|
CVE-2018-17126
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246364
|
7.5 |
HIGH
Network
|
chshcms
|
cscms
|
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
|
CWE-22
Path Traversal
|
CVE-2018-17125
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246365
|
6.1 |
MEDIUM
Network
|
easycms
|
easycms
|
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17113
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246366
|
9.8 |
CRITICAL
Network
|
tecdiary
|
simple_pos
|
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
|
CWE-89
SQL Injection
|
CVE-2018-17110
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246367
|
8.8 |
HIGH
Network
|
sbi
|
sbi_buddy
|
The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-question response during the initial confi…
|
NVD-CWE-noinfo
|
CVE-2018-17108
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246368
|
7.5 |
HIGH
Network
|
tinyftp_project
|
tinyftp
|
In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An attacker can overwrite ebp via a long pathname.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-17106
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246369
|
8.8 |
HIGH
Network
|
microweber
|
microweber
|
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
|
CWE-352
Origin Validation Error
|
CVE-2018-17104
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246370
|
8.8 |
HIGH
Network
|
get-simple
|
getsimple_cms
|
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending…
|
CWE-352
Origin Validation Error
|
CVE-2018-17103
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|