|
222821
|
9.8 |
CRITICAL
Network
|
netsarang
|
xftp
|
NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17320
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222822
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17434
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222823
|
4.8 |
MEDIUM
Network
|
laravel-admin
|
laravel-admin
|
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17433
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222824
|
6.5 |
MEDIUM
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-17432
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222825
|
8.8 |
HIGH
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2019-17431
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222826
|
6.1 |
MEDIUM
Network
|
eyoucms
|
eyoucms
|
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17430
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222827
|
9.8 |
CRITICAL
Network
|
adhouma_cms_project
|
adhouma_cms
|
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17429
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222828
|
6.1 |
MEDIUM
Network
|
redmine
|
redmine
|
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17427
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222829
|
9.1 |
CRITICAL
Network
|
mongoosejs
|
mongoose
|
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" …
|
NVD-CWE-noinfo
|
CVE-2019-17426
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222830
|
5.3 |
MEDIUM
Network
|
suricata-ids oisf
|
suricata libhtp
|
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
|
CWE-459
Incomplete Cleanup
|
CVE-2019-17420
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|