|
211241
|
8.8 |
HIGH
Network
|
directadmin
|
directadmin
|
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
|
CWE-352
Origin Validation Error
|
CVE-2019-9625
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211242
|
7.8 |
HIGH
Local
|
webmin
|
webmin
|
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
|
CWE-269
Improper Privilege Management
|
CVE-2019-9624
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211243
|
9.8 |
CRITICAL
Network
|
fengoffice
|
feng_office
|
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9623
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211244
|
4.3 |
MEDIUM
Network
|
ebrigade
|
ebrigade
|
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file.
|
CWE-22
Path Traversal
|
CVE-2019-9622
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211245
|
8.8 |
HIGH
Network
|
ofcms_project
|
ofcms
|
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/uedito…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9617
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211246
|
7.2 |
HIGH
Network
|
ofcms_project
|
ofcms
|
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/uedito…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-9616
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211247
|
7.2 |
HIGH
Network
|
ofcms_project
|
ofcms
|
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
|
CWE-89
SQL Injection
|
CVE-2019-9615
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211248
|
8.8 |
HIGH
Network
|
ofcms_project
|
ofcms
|
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the com…
|
CWE-74
Injection
|
CVE-2019-9614
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211249
|
7.2 |
HIGH
Network
|
ofcms_project
|
ofcms
|
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/uedito…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9613
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211250
|
8.8 |
HIGH
Network
|
ofcms_project
|
ofcms
|
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/s…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9612
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|