|
247281
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or…
|
CWE-94
Code Injection
|
CVE-2018-19002
|
2024-11-21 12:57 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247282
|
5.3 |
MEDIUM
Network
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
|
CWE-287
Improper Authentication
|
CVE-2018-19000
|
2024-11-21 12:57 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247283
|
9.8 |
CRITICAL
Network
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-18998
|
2024-11-21 12:57 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247284
|
9.8 |
CRITICAL
Network
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.
|
CWE-862
Missing Authorization
|
CVE-2018-18996
|
2024-11-21 12:57 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247285
|
8.8 |
HIGH
Network
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.
|
CWE-74
Injection
|
CVE-2018-18992
|
2024-11-21 12:57 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247286
|
3.3 |
LOW
Local
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-19004
|
2024-11-21 12:57 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247287
|
5.3 |
MEDIUM
Network
|
media_file_manager_project
|
media_file_manager
|
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename act…
|
CWE-22
Path Traversal
|
CVE-2018-19043
|
2024-11-21 12:57 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247288
|
5.3 |
MEDIUM
Network
|
media_file_manager_project
|
media_file_manager
|
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin…
|
CWE-22
Path Traversal
|
CVE-2018-19042
|
2024-11-21 12:57 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247289
|
6.1 |
MEDIUM
Network
|
media_file_manager_project
|
media_file_manager
|
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19041
|
2024-11-21 12:57 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247290
|
5.3 |
MEDIUM
Network
|
media_file_manager_project
|
media_file_manager
|
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
|
CWE-22
Path Traversal
|
CVE-2018-19040
|
2024-11-21 12:57 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|