|
246391
|
5.5 |
MEDIUM
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could e…
|
CWE-200
Information Exposure
|
CVE-2018-17482
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246392
|
8.8 |
HIGH
Network
|
jtbc
|
jtbc
|
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-17429
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246393
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17426
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246394
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17425
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246395
|
6.1 |
MEDIUM
Network
|
dotcms
|
dotcms
|
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
|
CWE-601
Open Redirect
|
CVE-2018-17422
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246396
|
6.1 |
MEDIUM
Network
|
zrlog
|
zrlog
|
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17421
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246397
|
7.2 |
HIGH
Network
|
zrlog
|
zrlog
|
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17420
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246398
|
7.5 |
HIGH
Network
|
dns_library_project
|
dns_library
|
An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17419
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246399
|
7.2 |
HIGH
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.p…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-17418
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246400
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17416
|
2024-11-21 12:54 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|