|
211911
|
6.5 |
MEDIUM
Network
|
custom_t-shirt_ecommerce_script_project
|
custom_t-shirt_ecommerce_script
|
PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount.
|
NVD-CWE-noinfo
|
CVE-2019-9065
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211912
|
5.3 |
MEDIUM
Network
|
cab_booking_script_project
|
cab_booking_script
|
PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file.
|
CWE-22
Path Traversal
|
CVE-2019-9064
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211913
|
6.5 |
MEDIUM
Network
|
auction_website_script_project
|
auction_website_script
|
PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount.
|
NVD-CWE-noinfo
|
CVE-2019-9063
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211914
|
8.0 |
HIGH
Network
|
phpscriptsmall
|
online_food_ordering_script
|
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-9062
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211915
|
9.8 |
CRITICAL
Network
|
fizzday
|
gorose
|
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
|
CWE-89
SQL Injection
|
CVE-2019-9047
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211916
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9052
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211917
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9051
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211918
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9050
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211919
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9049
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211920
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9048
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|