|
222791
|
4.8 |
MEDIUM
Network
|
hotarucms
|
hotarucms
|
A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17522
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222792
|
6.5 |
MEDIUM
Network
|
landing-cms_project
|
landing-cms
|
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
|
CWE-352
Origin Validation Error
|
CVE-2019-17521
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222793
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell met…
|
CWE-78
OS Command
|
CVE-2019-17510
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222794
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with she…
|
CWE-78
OS Command
|
CVE-2019-17509
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222795
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-859_a3_firmware dir-850l_a_firmware
|
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
|
CWE-78
OS Command
|
CVE-2019-17508
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222796
|
7.5 |
HIGH
Network
|
dlink
|
dir-816_a1_firmware
|
An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top.location.href = "/dir_login.asp"' line in a .asp …
|
CWE-20
Improper Input Validation
|
CVE-2019-17507
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222797
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-868l_b1_firmware dir-817lw_a1_firmware
|
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other informati…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17506
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222798
|
7.5 |
HIGH
Network
|
dlink
|
dap-1320_a2_firmware
|
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, wh…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17505
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222799
|
6.1 |
MEDIUM
Network
|
kirona
|
dynamic_resource_scheduling
|
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/r…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17504
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222800
|
9.8 |
CRITICAL
Network
|
fasterxml debian redhat oracle netapp
|
jackson-databind debian_linux jboss_enterprise_application_platform banking_platform jd_edwards_enterpriseone_tools primavera_gateway weblogic_server webcenter_portal webcente…
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17531
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|