|
246751
|
5.4 |
MEDIUM
Network
|
showdoc
|
showdoc
|
ShowDoc v1.8.0 has XSS via a new page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16342
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246752
|
8.8 |
HIGH
Network
|
phome
|
empirecms
|
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
|
CWE-352
Origin Validation Error
|
CVE-2018-16339
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246753
|
8.8 |
HIGH
Network
|
auracms
|
auracms
|
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
|
CWE-352
Origin Validation Error
|
CVE-2018-16338
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246754
|
6.5 |
MEDIUM
Network
|
chshcms
|
cscms
|
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
|
CWE-352
Origin Validation Error
|
CVE-2018-16337
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246755
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16336
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246756
|
8.8 |
HIGH
Network
|
libtiff debian
|
libtiff debian_linux
|
newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possi…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16335
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246757
|
8.8 |
HIGH
Network
|
tendacn
|
ac10_firmware ac9_firmware
|
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.
|
CWE-78
OS Command
|
CVE-2018-16334
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246758
|
7.5 |
HIGH
Network
|
tendacn
|
ac18_firmware ac15_firmware ac10_firmware ac9_firmware ac7_firmware
|
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnera…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16333
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246759
|
8.8 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2018-16332
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246760
|
8.8 |
HIGH
Network
|
damicms
|
damicms
|
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
|
CWE-352
Origin Validation Error
|
CVE-2018-16331
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|