|
246331
|
7.2 |
HIGH
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl…
|
CWE-20
Improper Input Validation
|
CVE-2018-16238
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246332
|
2.7 |
LOW
Network
|
damicms
|
damicms
|
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
|
CWE-22
Path Traversal
|
CVE-2018-16237
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246333
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16236
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246334
|
6.1 |
MEDIUM
Network
|
morningstarsecurity
|
whatweb
|
MorningStar WhatWeb 0.4.9 has XSS via JSON report files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16234
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246335
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16233
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246336
|
7.5 |
HIGH
Network
|
michael-roth-software
|
pftp
|
Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.
|
CWE-20
Improper Input Validation
|
CVE-2018-16231
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246337
|
9.8 |
CRITICAL
Network
|
codemenschen
|
gift_vouchers
|
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
|
CWE-89
SQL Injection
|
CVE-2018-16159
|
2024-11-21 12:52 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246338
|
5.3 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals para…
|
NVD-CWE-noinfo
|
CVE-2018-16157
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246339
|
7.5 |
HIGH
Network
|
lightbend
|
akka_http
|
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16131
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246340
|
9.8 |
CRITICAL
Network
|
eaton
|
power_xpert_meter_4000_firmware power_xpert_meter_6000_firmware power_xpert_meter_8000_firmware
|
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which ma…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-16158
|
2024-11-21 12:52 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|