|
248691
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
article_factory_manager
|
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17380
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248692
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
raffle_factory
|
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17379
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248693
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
penny_auction_factory
|
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17378
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248694
|
9.8 |
CRITICAL
Network
|
extensiondeveloper
|
questions
|
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17377
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248695
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
reverse_auction_factory
|
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17376
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248696
|
9.8 |
CRITICAL
Network
|
joomlathat
|
music_collection
|
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17375
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248697
|
9.8 |
CRITICAL
Network
|
viabtc
|
viabtc_exchange_server
|
utils/ut_ws_svr.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17570
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248698
|
9.8 |
CRITICAL
Network
|
viabtc
|
viabtc_exchange_server
|
network/nw_buf.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17569
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248699
|
9.8 |
CRITICAL
Network
|
viabtc
|
viabtc_exchange_server
|
utils/ut_rpc.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17568
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248700
|
9.8 |
CRITICAL
Network
|
informationbuilders
|
data_quality_suite
|
An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.
|
CWE-611
XXE
|
CVE-2018-17411
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|