|
247251
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
|
CWE-89
SQL Injection
|
CVE-2018-15168
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247252
|
9.8 |
CRITICAL
Network
|
cela_link
|
clr-m20_firmware
|
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-15137
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247253
|
7.5 |
HIGH
Network
|
php netapp
|
php storage_automation_store
|
An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the ope…
|
CWE-200
Information Exposure
|
CVE-2018-15132
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247254
|
5.4 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15130
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247255
|
5.4 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15129
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247256
|
8.8 |
HIGH
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-14978
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247257
|
6.1 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14977
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247258
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14976
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247259
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14975
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247260
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14974
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|