|
247411
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
|
CWE-89
SQL Injection
|
CVE-2018-19312
|
2024-11-21 12:57 |
2018-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247412
|
5.4 |
MEDIUM
Network
|
centreon
|
centreon
|
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19311
|
2024-11-21 12:57 |
2018-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247413
|
8.8 |
HIGH
Network
|
phpmailer_project debian fedoraproject wordpress
|
phpmailer debian_linux fedora wordpress
|
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
|
CWE-502 CWE-1321
Deserialization of Untrusted Data Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2018-19296
|
2024-11-21 12:57 |
2018-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247414
|
6.1 |
MEDIUM
Network
|
tp4a
|
teleport
|
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19301
|
2024-11-21 12:57 |
2018-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247415
|
6.5 |
MEDIUM
Network
|
dilicms
|
dilicms
|
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-19291
|
2024-11-21 12:57 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247416
|
6.1 |
MEDIUM
Network
|
valine.js
|
valine
|
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19289
|
2024-11-21 12:57 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247417
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19288
|
2024-11-21 12:57 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247418
|
6.1 |
MEDIUM
Network
|
ninjaforma
|
ninja_forms
|
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or fo…
|
CWE-79
Cross-site Scripting
|
CVE-2018-19287
|
2024-11-21 12:57 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247419
|
6.1 |
MEDIUM
Network
|
mubu
|
curtain
|
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19286
|
2024-11-21 12:57 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247420
|
9.8 |
CRITICAL
Network
|
centreon
|
centreon
|
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2018-19281
|
2024-11-21 12:57 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|