|
213861
|
6.5 |
MEDIUM
Network
|
rental_bike_script_project
|
rental_bike_script
|
PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.
|
CWE-200
Information Exposure
|
CVE-2019-7434
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213862
|
8.8 |
HIGH
Network
|
rental_bike_script_project
|
rental_bike_script
|
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
|
CWE-352
Origin Validation Error
|
CVE-2019-7433
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213863
|
5.4 |
MEDIUM
Network
|
rental_bike_script_project
|
rental_bike_script
|
PHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7432
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213864
|
6.5 |
MEDIUM
Network
|
image_sharing_script_project
|
image_sharing_script
|
PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.
|
CWE-200
Information Exposure
|
CVE-2019-7431
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213865
|
5.3 |
MEDIUM
Network
|
image_sharing_script_project
|
image_sharing_script
|
PHP Scripts Mall Image Sharing Script 1.3.4 has HTML injection via the Search Bar.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7430
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213866
|
6.5 |
MEDIUM
Network
|
property_rental_software_project
|
property_rental_software
|
PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2016/08 directory.
|
CWE-200
Information Exposure
|
CVE-2019-7429
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213867
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7425
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213868
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTim…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7424
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213869
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7423
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213870
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7422
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|