|
250131
|
6.5 |
MEDIUM
Network
|
open-emr
|
openemr
|
interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
|
NVD-CWE-noinfo
|
CVE-2018-10572
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250132
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10570
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250133
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/fin…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10571
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250134
|
7.5 |
HIGH
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.
|
CWE-269
Improper Privilege Management
|
CVE-2018-10550
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250135
|
5.4 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting;…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-10554
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250136
|
6.5 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindo…
|
CWE-22
Path Traversal
|
CVE-2018-10553
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250137
|
8.8 |
HIGH
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data becau…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10549
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250138
|
7.5 |
HIGH
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10548
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250139
|
6.1 |
MEDIUM
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages vi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10547
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250140
|
7.5 |
HIGH
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not r…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-10546
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|