|
247261
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14973
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247262
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14972
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247263
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14971
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247264
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14970
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247265
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14969
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247266
|
9.8 |
CRITICAL
Network
|
emlsoft_project
|
emlsoft
|
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.address.php has SQL Injection via the numPerPage parameter.
|
CWE-89
SQL Injection
|
CVE-2018-14968
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247267
|
8.8 |
HIGH
Network
|
emlsoft_project
|
emlsoft
|
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.user.php has SQL Injection via the numPerPage parameter.
|
CWE-89
SQL Injection
|
CVE-2018-14967
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247268
|
8.8 |
HIGH
Network
|
emlsoft_project
|
emlsoft
|
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-14966
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247269
|
8.8 |
HIGH
Network
|
emlsoft_project
|
emlsoft
|
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-14965
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247270
|
5.4 |
MEDIUM
Network
|
emlsoft_project
|
emlsoft
|
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14964
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|