|
222611
|
9.8 |
CRITICAL
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.
|
NVD-CWE-noinfo
|
CVE-2019-15088
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222612
|
7.2 |
HIGH
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution.
|
CWE-94
Code Injection
|
CVE-2019-15087
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222613
|
6.1 |
MEDIUM
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15086
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222614
|
7.5 |
HIGH
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.
|
CWE-200
Information Exposure
|
CVE-2019-15085
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222615
|
9.8 |
CRITICAL
Network
|
terrasoft
|
bpm_online_crm_system_sdk
|
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
|
CWE-89
SQL Injection
|
CVE-2019-15301
|
2024-11-21 13:28 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222616
|
9.8 |
CRITICAL
Network
|
code42
|
code42
|
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerabi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15131
|
2024-11-21 13:28 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222617
|
6.5 |
MEDIUM
Network
|
xwiki
|
cryptpad
|
The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a t…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2019-15302
|
2024-11-21 13:28 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222618
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15297
|
2024-11-21 13:28 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222619
|
6.5 |
MEDIUM
Network
|
if.svnadmin_project
|
if.svnadmin
|
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
|
CWE-352
Origin Validation Error
|
CVE-2019-15128
|
2024-11-21 13:28 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222620
|
9.8 |
CRITICAL
Network
|
sahipro
|
sahi_pro
|
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an ar…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15102
|
2024-11-21 13:28 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|