|
246711
|
6.5 |
MEDIUM
Network
|
ignitedcms
|
ignitedcms
|
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
|
CWE-352
Origin Validation Error
|
CVE-2018-15203
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246712
|
6.3 |
MEDIUM
Network
|
juunan06
|
ecommerce
|
An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.php that can add new users and add products.
|
CWE-352
Origin Validation Error
|
CVE-2018-15202
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246713
|
5.4 |
MEDIUM
Network
|
auracms
|
auracms
|
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15199
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246714
|
8.8 |
HIGH
Network
|
onethink
|
onethink
|
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.
|
CWE-352
Origin Validation Error
|
CVE-2018-15198
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246715
|
8.8 |
HIGH
Network
|
onethink
|
onethink
|
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges.
|
CWE-352
Origin Validation Error
|
CVE-2018-15197
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246716
|
8.8 |
HIGH
Network
|
gogs
|
gogs
|
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
|
CWE-352
Origin Validation Error
|
CVE-2018-15193
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246717
|
8.6 |
HIGH
Network
|
gogs gitea
|
gogs gitea
|
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-15192
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246718
|
6.1 |
MEDIUM
Network
|
gogs
|
gogs
|
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to …
|
CWE-601
Open Redirect
|
CVE-2018-15178
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246719
|
8.8 |
HIGH
Network
|
gxlcms
|
gxlcms
|
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-15177
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246720
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact vi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15176
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|