|
214321
|
6.1 |
MEDIUM
Network
|
topnew
|
sidu
|
An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7546
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214322
|
5.4 |
MEDIUM
Network
|
dbninja
|
dbninja
|
In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7545
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214323
|
5.4 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name Field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7544
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214324
|
6.1 |
MEDIUM
Network
|
kindsoft
|
kindeditor
|
In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7543
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214325
|
6.1 |
MEDIUM
Network
|
parallax_scroll_project
|
parallax_scroll
|
In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7413
|
2024-11-21 13:48 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214326
|
9.8 |
CRITICAL
Network
|
ps_phpcaptcha_wp_project
|
ps_phpcaptcha_wp
|
The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.
|
CWE-20
Improper Input Validation
|
CVE-2019-7412
|
2024-11-21 13:48 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214327
|
4.9 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
An issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&tbname=../ URI.
|
CWE-22
Path Traversal
|
CVE-2019-7403
|
2024-11-21 13:48 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214328
|
6.1 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-7402
|
2024-11-21 13:48 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214329
|
6.1 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Rukovoditel before 2.4.1 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7400
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214330
|
7.5 |
HIGH
Network
|
imagemagick opensuse debian canonical
|
imagemagick leap debian_linux ubuntu_linux
|
In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7398
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|