|
212591
|
6.1 |
MEDIUM
Network
|
dbninja
|
dbninja
|
_includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7748
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212592
|
9.6 |
CRITICAL
Network
|
dbninja
|
dbninja
|
DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
|
CWE-384
Session Fixation
|
CVE-2019-7747
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212593
|
6.5 |
MEDIUM
Network
|
c.p.sub_project
|
c.p.sub
|
C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-7738
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212594
|
8.8 |
HIGH
Network
|
verydows
|
verydows
|
A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
|
CWE-352
Origin Validation Error
|
CVE-2019-7737
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212595
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-600m_firmware
|
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-7736
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212596
|
7.5 |
HIGH
Network
|
live555
|
streaming_media
|
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-7733
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212597
|
7.5 |
HIGH
Network
|
live555
|
streaming_media
|
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7732
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212598
|
9.8 |
CRITICAL
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's arc…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-7731
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212599
|
5.7 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-7730
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212600
|
8.1 |
HIGH
Network
|
pmd_project
|
pmd
|
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when u…
|
CWE-611
XXE
|
CVE-2019-7722
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|