|
223031
|
5.4 |
MEDIUM
Network
|
syguestbook_a5_project
|
syguestbook_a5
|
index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13950
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223032
|
8.8 |
HIGH
Network
|
syguestbook_a5_project
|
syguestbook_a5
|
SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.
|
CWE-352
Origin Validation Error
|
CVE-2019-13949
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223033
|
5.4 |
MEDIUM
Network
|
syguestbook_a5_project
|
syguestbook_a5
|
SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute …
|
CWE-79
Cross-site Scripting
|
CVE-2019-13948
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223034
|
7.5 |
HIGH
Network
|
docker
|
docker
|
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-13509
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223035
|
7.5 |
HIGH
Network
|
b3log
|
wide
|
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrar…
|
CWE-59 CWE-74
Link Following Injection
|
CVE-2019-13915
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223036
|
6.1 |
MEDIUM
Network
|
opera
|
mini
|
The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to a javascript: URL.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13607
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223037
|
9.8 |
CRITICAL
Network
|
wpeverest
|
everest_forms
|
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQ…
|
CWE-89
SQL Injection
|
CVE-2019-13575
|
2024-11-21 13:25 |
2019-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223038
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attach…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13647
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223039
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13646
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223040
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachme…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13645
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|