1301
|
- |
|
-
|
-
|
A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is pos…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2024-13203
|
2025-01-9 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1302
|
- |
|
-
|
-
|
A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admi…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13202
|
2025-01-9 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1303
|
- |
|
-
|
-
|
A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/ad…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13201
|
2025-01-9 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1304
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInter…
|
CWE-284 CWE-266
Improper Access Control Incorrect Privilege Assignment
|
CVE-2024-13200
|
2025-01-9 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1305
|
- |
|
-
|
-
|
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
|
-
|
CVE-2024-37372
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1306
|
- |
|
-
|
-
|
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the sh…
|
-
|
CVE-2024-27980
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1307
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13199
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1308
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepa…
|
CWE-203 CWE-204
Information Exposure Through Discrepancy Response Discrepancy Information Exposure
|
CVE-2024-13198
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1309
|
- |
|
-
|
-
|
ActiveSupport::EncryptedFile writes contents that will be encrypted to a
temporary file. The temporary file's permissions are defaulted to the user's
current `umask` settings, meaning that it's po…
|
-
|
CVE-2023-38037
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1310
|
- |
|
-
|
-
|
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compl…
|
-
|
CVE-2023-28362
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|