|
223471
|
6.5 |
MEDIUM
Network
|
phpbb
|
phpbb
|
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-13376
|
2024-11-21 13:24 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223472
|
7.8 |
HIGH
Local
|
totaldefense
|
anti-virus
|
In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTE…
|
CWE-426
Untrusted Search Path
|
CVE-2019-13357
|
2024-11-21 13:24 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223473
|
7.8 |
HIGH
Local
|
totaldefense
|
anti-virus
|
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-13356
|
2024-11-21 13:24 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223474
|
7.8 |
HIGH
Local
|
totaldefense
|
anti-virus
|
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hijack dotnetproxy.exe…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-13355
|
2024-11-21 13:24 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223475
|
7.5 |
HIGH
Network
|
sahipro
|
sahi_pro
|
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.…
|
CWE-22
Path Traversal
|
CVE-2019-13063
|
2024-11-21 13:24 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223476
|
6.5 |
MEDIUM
Network
|
intenogroup
|
eg200_firmware
|
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to de…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2019-13140
|
2024-11-21 13:24 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223477
|
9.8 |
CRITICAL
Network
|
telestar
|
bobs_rock_radio_firmware dabman_d10_firmware dabman_i30_stereo_firmware imperial_i110_firmware imperial_i150_firmware imperial_i200_firmware imperial_i200-cd_firmware imperial_i4…
|
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13474
|
2024-11-21 13:24 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223478
|
9.6 |
CRITICAL
Network
|
piwigo
|
piwigo
|
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-13364
|
2024-11-21 13:24 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223479
|
9.6 |
CRITICAL
Network
|
piwigo
|
piwigo
|
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-13363
|
2024-11-21 13:24 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223480
|
9.8 |
CRITICAL
Network
|
telestar auna
|
bobs_rock_radio_firmware dabman_d10_firmware dabman_i30_stereo_firmware imperial_i110_firmware imperial_i150_firmware imperial_i200_firmware imperial_i200-cd_firmware imperial_i4…
|
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13473
|
2024-11-21 13:24 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|