|
246411
|
8.8 |
HIGH
Network
|
ucms_project
|
ucms
|
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-17037
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246412
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into…
|
CWE-94
Code Injection
|
CVE-2018-17036
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246413
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17035
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246414
|
6.1 |
MEDIUM
Network
|
ucms_project
|
ucms
|
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17034
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246415
|
6.1 |
MEDIUM
Network
|
gogs
|
gogs
|
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header i…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17031
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246416
|
7.5 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
|
CWE-94
Code Injection
|
CVE-2018-17030
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246417
|
4.8 |
MEDIUM
Network
|
monstra
|
monstra
|
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17026
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246418
|
6.1 |
MEDIUM
Network
|
monstra
|
monstra
|
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17025
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246419
|
4.8 |
MEDIUM
Network
|
monstra
|
monstra
|
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17024
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246420
|
8.8 |
HIGH
Network
|
asus
|
gt-ac5300_firmware
|
Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows remote attackers to hijack the authentication of administrators for requests t…
|
CWE-352
Origin Validation Error
|
CVE-2018-17023
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|