|
246901
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
|
CWE-89
SQL Injection
|
CVE-2018-17136
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246902
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.
|
CWE-94
Code Injection
|
CVE-2018-17134
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246903
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
|
CWE-94
Code Injection
|
CVE-2018-17133
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246904
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
|
CWE-94
Code Injection
|
CVE-2018-17132
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246905
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
|
CWE-94
Code Injection
|
CVE-2018-17131
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246906
|
5.4 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
|
CWE-79
Cross-site Scripting
|
CVE-2018-17130
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246907
|
4.9 |
MEDIUM
Network
|
metinfo
|
metinfo
|
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
|
CWE-89
SQL Injection
|
CVE-2018-17129
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246908
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17128
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246909
|
7.5 |
HIGH
Network
|
asus
|
gt-ac5300_firmware
|
blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a ti…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17127
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246910
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
|
CWE-94
Code Injection
|
CVE-2018-17126
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|