|
222691
|
6.1 |
MEDIUM
Network
|
hgw168cc
|
yii-cms
|
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16130
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222692
|
6.1 |
MEDIUM
Network
|
getgrav
|
grav_cms
|
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16126
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222693
|
9.8 |
CRITICAL
Network
|
jobberbase
|
jobberbase
|
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-16125
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222694
|
9.8 |
CRITICAL
Network
|
youphptube
|
youphptube
|
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
|
CWE-862
Missing Authorization
|
CVE-2019-16124
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222695
|
7.5 |
HIGH
Network
|
kartatopia
|
piluscart
|
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
|
CWE-22
Path Traversal
|
CVE-2019-16123
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222696
|
8.8 |
HIGH
Network
|
tri
|
event_tickets
|
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-16120
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222697
|
9.8 |
CRITICAL
Network
|
10web
|
photo_gallery
|
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-16119
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222698
|
6.1 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16118
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222699
|
6.1 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16117
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222700
|
7.8 |
HIGH
Local
|
glyphandcog
|
xpdfreader
|
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a cr…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16115
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|