|
246771
|
6.1 |
MEDIUM
Network
|
matera
|
banco
|
Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14929
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246772
|
7.5 |
HIGH
Network
|
matera
|
banco
|
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.
|
CWE-200
Information Exposure
|
CVE-2018-14928
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246773
|
5.3 |
MEDIUM
Network
|
matera
|
banco
|
Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application folder) via the /contingency/servlet/ServletFileDownload file parameter, related to…
|
CWE-22
Path Traversal
|
CVE-2018-14927
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246774
|
8.8 |
HIGH
Network
|
matera
|
banco
|
Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
|
CWE-352
Origin Validation Error
|
CVE-2018-14926
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246775
|
9.8 |
CRITICAL
Network
|
matera
|
banco
|
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2018-14925
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246776
|
6.1 |
MEDIUM
Network
|
matera
|
banco
|
Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14924
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246777
|
7.8 |
HIGH
Local
|
uniview
|
ezplayer
|
A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback.
|
CWE-20
Improper Input Validation
|
CVE-2018-14923
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246778
|
7.5 |
HIGH
Network
|
cgit_project debian
|
cgit debian_linux
|
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
|
CWE-22
Path Traversal
|
CVE-2018-14912
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246779
|
7.2 |
HIGH
Network
|
ukcms
|
ukcms
|
A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering the file upload type. An attacker can exploit the vulnerability to upload…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-14911
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246780
|
8.8 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php o…
|
CWE-352 CWE-94
Origin Validation Error Code Injection
|
CVE-2018-14910
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|