|
246941
|
9.8 |
CRITICAL
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2018-16239
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246942
|
7.2 |
HIGH
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl…
|
CWE-20
Improper Input Validation
|
CVE-2018-16238
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246943
|
2.7 |
LOW
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
|
CWE-22
Path Traversal
|
CVE-2018-16237
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246944
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16236
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246945
|
6.1 |
MEDIUM
Network
|
morningstarsecurity
|
whatweb
|
MorningStar WhatWeb 0.4.9 has XSS via JSON report files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16234
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246946
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16233
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246947
|
7.5 |
HIGH
Network
|
michael-roth-software
|
pftp
|
Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.
|
CWE-20
Improper Input Validation
|
CVE-2018-16231
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246948
|
9.8 |
CRITICAL
Network
|
codemenschen
|
gift_vouchers
|
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
|
CWE-89
SQL Injection
|
CVE-2018-16159
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246949
|
5.3 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals para…
|
NVD-CWE-noinfo
|
CVE-2018-16157
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246950
|
7.5 |
HIGH
Network
|
lightbend
|
akka_http
|
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16131
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|