|
246081
|
9.8 |
CRITICAL
Network
|
extensiondeveloper
|
questions
|
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17377
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246082
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
reverse_auction_factory
|
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17376
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246083
|
9.8 |
CRITICAL
Network
|
joomlathat
|
music_collection
|
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17375
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246084
|
9.8 |
CRITICAL
Network
|
viabtc
|
viabtc_exchange_server
|
utils/ut_ws_svr.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17570
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246085
|
9.8 |
CRITICAL
Network
|
viabtc
|
viabtc_exchange_server
|
network/nw_buf.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17569
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246086
|
9.8 |
CRITICAL
Network
|
viabtc
|
viabtc_exchange_server
|
utils/ut_rpc.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17568
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246087
|
9.8 |
CRITICAL
Network
|
informationbuilders
|
data_quality_suite
|
An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.
|
CWE-611
XXE
|
CVE-2018-17411
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246088
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c6003_firmware
|
On the RICOH MP C6003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWiz…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17316
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246089
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c2003sp_firmware
|
On the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWiz…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17315
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246090
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_305\+_firmware
|
On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetU…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17314
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|