|
210981
|
8.8 |
HIGH
Network
|
kartatopia
|
piluscart
|
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
|
CWE-352
Origin Validation Error
|
CVE-2019-9769
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210982
|
7.5 |
HIGH
Network
|
thinkst
|
canarytokens
|
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document con…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2019-9768
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210983
|
7.8 |
HIGH
Local
|
cleanersoft
|
free_mp3_cd_ripper
|
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wma file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9767
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210984
|
7.8 |
HIGH
Local
|
cleanersoft
|
free_mp3_cd_ripper
|
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .mp3 file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9766
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210985
|
6.1 |
MEDIUM
Network
|
blog_mini_project
|
blog_mini
|
In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9765
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210986
|
9.8 |
CRITICAL
Network
|
phpshe
|
phpshe
|
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
|
CWE-89
SQL Injection
|
CVE-2019-9762
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210987
|
7.5 |
HIGH
Network
|
phpshe
|
phpshe
|
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in in…
|
CWE-611
XXE
|
CVE-2019-9761
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210988
|
9.8 |
CRITICAL
Network
|
ftpgetter
|
ftpgetter
|
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses. Long responses can also crash the …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9760
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210989
|
5.5 |
MEDIUM
Local
|
tinycc
|
tinycc
|
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byte out of bounds write in the end_macro function in tccpp.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9754
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210990
|
5.4 |
MEDIUM
Network
|
otrs opensuse
|
otrs leap backports_sle
|
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload …
|
CWE-79
Cross-site Scripting
|
CVE-2019-9752
|
2024-11-21 13:52 |
2019-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|