|
222531
|
4.7 |
MEDIUM
Network
|
traveloka
|
traveloka
|
The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16681
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222532
|
4.3 |
MEDIUM
Network
|
gnome redhat debian canonical
|
file-roller enterprise_linux debian_linux ubuntu_linux
|
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
|
CWE-22
Path Traversal
|
CVE-2019-16680
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222533
|
4.9 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
|
CWE-22
Path Traversal
|
CVE-2019-16679
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222534
|
6.5 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
|
CWE-352
Origin Validation Error
|
CVE-2019-16678
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222535
|
6.5 |
MEDIUM
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16677
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222536
|
5.3 |
MEDIUM
Network
|
pagekit
|
pagekit
|
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumera…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16669
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222537
|
6.1 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBE…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16665
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222538
|
4.8 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16664
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222539
|
5.4 |
MEDIUM
Network
|
digimute
|
ogma_cms
|
Ogma CMS 0.5 has XSS via creation of a new blog.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16661
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222540
|
8.8 |
HIGH
Network
|
joyplus_project
|
joyplus
|
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16660
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|