|
246351
|
4.8 |
MEDIUM
Network
|
e107
|
e107
|
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17423
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246352
|
9.8 |
CRITICAL
Network
|
jimtawl_project
|
jimtawl
|
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17399
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246353
|
9.8 |
CRITICAL
Network
|
arenam
|
amgallery
|
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17398
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246354
|
9.8 |
CRITICAL
Network
|
healthnode_hospital_management_system_project
|
healthnode_hospital_management_system
|
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
|
CWE-89
SQL Injection
|
CVE-2018-17393
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246355
|
8.8 |
HIGH
Network
|
ranksol
|
live_call_support
|
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2018-17389
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246356
|
9.8 |
CRITICAL
Network
|
apache
|
roller
|
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and b…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-17198
|
2024-11-21 12:54 |
2019-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246357
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
|
CWE-89
SQL Injection
|
CVE-2018-17181
|
2024-11-21 12:54 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246358
|
5.3 |
MEDIUM
Network
|
open-emr
|
openemr
|
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
|
CWE-22
Path Traversal
|
CVE-2018-17180
|
2024-11-21 12:54 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246359
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.ph…
|
CWE-89
SQL Injection
|
CVE-2018-17179
|
2024-11-21 12:54 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246360
|
7.5 |
HIGH
Network
|
apache
|
commons_imaging
|
Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incu…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-17202
|
2024-11-21 12:54 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|