|
246311
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.
|
NVD-CWE-noinfo
|
CVE-2018-15881
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246312
|
5.4 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15880
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246313
|
6.5 |
MEDIUM
Network
|
website_seller_script_project
|
website_seller_script
|
PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax field, as demonstrated…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15897
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246314
|
5.4 |
MEDIUM
Network
|
website_seller_script_project
|
website_seller_script
|
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15896
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246315
|
8.8 |
HIGH
Network
|
e107
|
e107
|
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
|
CWE-352
Origin Validation Error
|
CVE-2018-15901
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246316
|
8.8 |
HIGH
Network
|
ricoh
|
mp_c4504ex_firmware
|
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-15884
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246317
|
9.8 |
CRITICAL
Network
|
sapplica
|
sentrifugo
|
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
|
CWE-89
SQL Injection
|
CVE-2018-15873
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246318
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_admanager_plus
|
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15740
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246319
|
6.1 |
MEDIUM
Network
|
manageengine
|
admanager_plus
|
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15608
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246320
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. …
|
CWE-79
Cross-site Scripting
|
CVE-2018-15596
|
2024-11-21 12:51 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|