|
246951
|
6.1 |
MEDIUM
Network
|
cqu_lankers_project
|
cqu_lankers
|
CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17049
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246952
|
6.1 |
MEDIUM
Network
|
translate_man_project
|
translate_man
|
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17046
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246953
|
8.8 |
HIGH
Network
|
cms_maelostore_project
|
cms_maelostore
|
An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aksi_users.php?act=update.
|
CWE-352
Origin Validation Error
|
CVE-2018-17045
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246954
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17044
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246955
|
7.8 |
HIGH
Local
|
doc2txt_project
|
doc2txt
|
An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init in Storage.cpp, called from parse_doc in parse_doc.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17043
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246956
|
5.5 |
MEDIUM
Local
|
scalabium
|
dbf2txt
|
An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-17042
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246957
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17039
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246958
|
8.8 |
HIGH
Network
|
ucms_project
|
ucms
|
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-17037
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246959
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into…
|
CWE-94
Code Injection
|
CVE-2018-17036
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246960
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17035
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|