|
246291
|
7.2 |
HIGH
Network
|
dasannetworks
|
h660gw_firmware
|
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP…
|
CWE-78
OS Command
|
CVE-2018-17867
|
2024-11-21 12:55 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246292
|
6.5 |
MEDIUM
Network
|
simdcomp_project
|
simdcomp
|
SIMDComp before 0.1.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes. NOTE: this issue exi…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17854
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246293
|
9.8 |
CRITICAL
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.
|
CWE-89
SQL Injection
|
CVE-2018-17852
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246294
|
7.5 |
HIGH
Network
|
golang fedoraproject
|
net fedora
|
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-17848
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246295
|
7.5 |
HIGH
Network
|
golang fedoraproject
|
net fedora
|
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-17847
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246296
|
7.5 |
HIGH
Network
|
golang fedoraproject
|
net fedora
|
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectI…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-17846
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246297
|
7.5 |
HIGH
Network
|
jtbc
|
jtbc_php
|
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.
|
CWE-22
Path Traversal
|
CVE-2018-17838
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246298
|
7.5 |
HIGH
Network
|
jtbc
|
jtbc_php
|
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.
|
CWE-22
Path Traversal
|
CVE-2018-17837
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246299
|
8.8 |
HIGH
Network
|
jtbc
|
jtbc_php
|
An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, i…
|
CWE-22
Path Traversal
|
CVE-2018-17836
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246300
|
4.8 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page cr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17835
|
2024-11-21 12:55 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|