|
246931
|
2.7 |
LOW
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
|
CWE-22
Path Traversal
|
CVE-2018-16237
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246932
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16236
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246933
|
6.1 |
MEDIUM
Network
|
morningstarsecurity
|
whatweb
|
MorningStar WhatWeb 0.4.9 has XSS via JSON report files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16234
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246934
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16233
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246935
|
7.5 |
HIGH
Network
|
michael-roth-software
|
pftp
|
Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.
|
CWE-20
Improper Input Validation
|
CVE-2018-16231
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246936
|
9.8 |
CRITICAL
Network
|
codemenschen
|
gift_vouchers
|
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
|
CWE-89
SQL Injection
|
CVE-2018-16159
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246937
|
5.3 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals para…
|
NVD-CWE-noinfo
|
CVE-2018-16157
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246938
|
7.5 |
HIGH
Network
|
lightbend
|
akka_http
|
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16131
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246939
|
9.8 |
CRITICAL
Network
|
eaton
|
power_xpert_meter_4000_firmware power_xpert_meter_6000_firmware power_xpert_meter_8000_firmware
|
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which ma…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-16158
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246940
|
6.1 |
MEDIUM
Network
|
phpok
|
phpok
|
PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16142
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|