|
224161
|
9.8 |
CRITICAL
Network
|
squid-cache debian opensuse fedoraproject canonical
|
squid debian_linux leap fedora ubuntu_linux
|
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tok…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12525
|
2024-11-21 13:23 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224162
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12597
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224163
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12596
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224164
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12595
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224165
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12540
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224166
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12539
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224167
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12537
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224168
|
9.8 |
CRITICAL
Network
|
schedmd debian fedoraproject opensuse
|
slurm debian_linux fedora leap
|
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-12838
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224169
|
5.5 |
MEDIUM
Local
|
hunesion
|
i-onenet
|
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-12804
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224170
|
9.8 |
CRITICAL
Network
|
hunesion
|
i-onenet
|
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-12803
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|