|
223831
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to L…
|
CWE-78
OS Command
|
CVE-2019-15529
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223832
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to …
|
CWE-78
OS Command
|
CVE-2019-15528
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223833
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to …
|
CWE-78
OS Command
|
CVE-2019-15527
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223834
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWa…
|
CWE-78
OS Command
|
CVE-2019-15526
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223835
|
8.1 |
HIGH
Network
|
pw3270_project
|
pw3270
|
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15525
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223836
|
5.3 |
MEDIUM
Network
|
comelz
|
quark
|
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
|
CWE-22
Path Traversal
|
CVE-2019-15520
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223837
|
9.8 |
CRITICAL
Network
|
power-response_project
|
power-response
|
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
|
CWE-22
Path Traversal
|
CVE-2019-15519
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223838
|
5.3 |
MEDIUM
Network
|
swoole
|
swoole
|
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
|
CWE-22
Path Traversal
|
CVE-2019-15518
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223839
|
5.5 |
MEDIUM
Local
|
jc21
|
nginx_proxy_manager
|
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-15517
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223840
|
7.5 |
HIGH
Network
|
cuberite
|
cuberite
|
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.
|
CWE-22
Path Traversal
|
CVE-2019-15516
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|