|
246891
|
8.8 |
HIGH
Network
|
fledrcms_project
|
fledrcms
|
An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=done&savedata=1.
|
CWE-352
Origin Validation Error
|
CVE-2018-15846
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246892
|
8.8 |
HIGH
Network
|
gleezcms
|
gleez_cms
|
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
|
CWE-352
Origin Validation Error
|
CVE-2018-15845
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246893
|
8.8 |
HIGH
Network
|
damicms
|
damicms
|
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
|
CWE-352
Origin Validation Error
|
CVE-2018-15844
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246894
|
4.8 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15843
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246895
|
4.8 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15842
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246896
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-615_firmware
|
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SO…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15875
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246897
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-615_firmware
|
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15874
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246898
|
6.5 |
MEDIUM
Network
|
libming
|
libming
|
An invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 2018-03-12. The vulnerability causes a segmentation fault and application crash, …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15871
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246899
|
6.5 |
MEDIUM
Network
|
libming
|
libming
|
An invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vulnerability causes a segmentation fault and application crash, which leads to de…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15870
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246900
|
5.3 |
MEDIUM
Network
|
hashicorp
|
packer
|
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security be…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-15869
|
2024-11-21 12:51 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|