|
214251
|
6.1 |
MEDIUM
Network
|
verydows
|
verydows
|
Verydows 2.0 has XSS via the index.php?m=api&c=stats&a=count referrer parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7753
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214252
|
6.1 |
MEDIUM
Network
|
dbninja
|
dbninja
|
_includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7748
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214253
|
9.6 |
CRITICAL
Network
|
dbninja
|
dbninja
|
DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
|
CWE-384
Session Fixation
|
CVE-2019-7747
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214254
|
6.5 |
MEDIUM
Network
|
c.p.sub_project
|
c.p.sub
|
C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-7738
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214255
|
8.8 |
HIGH
Network
|
verydows
|
verydows
|
A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
|
CWE-352
Origin Validation Error
|
CVE-2019-7737
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214256
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-600m_firmware
|
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-7736
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214257
|
7.5 |
HIGH
Network
|
live555
|
streaming_media
|
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-7733
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214258
|
7.5 |
HIGH
Network
|
live555
|
streaming_media
|
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7732
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214259
|
9.8 |
CRITICAL
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's arc…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-7731
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214260
|
5.7 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-7730
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|