|
246521
|
7.2 |
HIGH
Network
|
thimpress
|
learnpress
|
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2018-16175
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246522
|
6.1 |
MEDIUM
Network
|
thimpress
|
learnpress
|
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
CWE-601
Open Redirect
|
CVE-2018-16174
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246523
|
6.1 |
MEDIUM
Network
|
thimpress
|
learnpress
|
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16173
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246524
|
6.5 |
MEDIUM
Network
|
cybozu
|
remote_service_manager
|
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to de…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2018-16172
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246525
|
8.8 |
HIGH
Network
|
cybozu
|
remote_service_manager
|
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-16171
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246526
|
8.1 |
HIGH
Network
|
cybozu
|
remote_service_manager
|
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-16170
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246527
|
8.8 |
HIGH
Network
|
cybozu
|
remote_service_manager
|
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16169
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246528
|
9.8 |
CRITICAL
Network
|
jpcert
|
logontracer
|
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2018-16168
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246529
|
9.8 |
CRITICAL
Network
|
jpcert
|
logontracer
|
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-16167
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246530
|
8.8 |
HIGH
Network
|
jpcert
|
logontracer
|
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
|
CWE-611
XXE
|
CVE-2018-16166
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|