|
212751
|
7.4 |
HIGH
Network
|
amazon
|
fire_os
|
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
|
CWE-346
Origin Validation Error
|
CVE-2019-7399
|
2024-11-21 13:48 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212752
|
5.3 |
MEDIUM
Network
|
jforum
|
jforum
|
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-7550
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212753
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7744
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212754
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper…
|
CWE-502 CWE-917
Deserialization of Untrusted Data Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2019-7743
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212755
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack …
|
CWE-79
Cross-site Scripting
|
CVE-2019-7742
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212756
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7741
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212757
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7740
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212758
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the…
|
NVD-CWE-noinfo
|
CVE-2019-7739
|
2024-11-21 13:48 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212759
|
6.1 |
MEDIUM
Network
|
verydows
|
verydows
|
Verydows 2.0 has XSS via the index.php?m=api&c=stats&a=count referrer parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7753
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212760
|
6.1 |
MEDIUM
Network
|
dbninja
|
dbninja
|
_includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7748
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|