|
211261
|
6.1 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9595
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211262
|
9.8 |
CRITICAL
Network
|
bluecms_project
|
bluecms
|
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
|
CWE-89
SQL Injection
|
CVE-2019-9594
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211263
|
6.1 |
MEDIUM
Network
|
mitel
|
connect_onsite
|
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9593
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211264
|
6.1 |
MEDIUM
Network
|
mitel
|
connect_onsite
|
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9592
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211265
|
6.1 |
MEDIUM
Network
|
mitel
|
connect_onsite
|
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9591
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211266
|
7.5 |
HIGH
Network
|
tengcon
|
t-920_plc_firmware
|
An issue was discovered on TENGCONTROL T-920 PLC v5.5 devices. It allows remote attackers to cause a denial of service (persistent failure mode) by sending a series of \x19\xb2\x00\x00\x00\x06\x43\x0…
|
NVD-CWE-noinfo
|
CVE-2019-9590
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211267
|
7.8 |
HIGH
Local
|
glyphandcog
|
xpdfreader
|
There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfto…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9589
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211268
|
7.8 |
HIGH
Local
|
glyphandcog
|
xpdfreader
|
There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9588
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211269
|
7.8 |
HIGH
Local
|
glyphandcog
|
xpdfreader
|
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-9587
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211270
|
8.8 |
HIGH
Network
|
twinkletoessoftware
|
booked
|
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresent…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9581
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|