|
223101
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userP…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17114
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223102
|
8.8 |
HIGH
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, u…
|
CWE-89
SQL Injection
|
CVE-2019-16917
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223103
|
9.8 |
CRITICAL
Network
|
slub-dresden
|
slub_events
|
The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execut…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16700
|
2024-11-21 13:31 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223104
|
9.8 |
CRITICAL
Network
|
sr_freecap_project
|
sr_freecap
|
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Cod…
|
CWE-20
Improper Input Validation
|
CVE-2019-16699
|
2024-11-21 13:31 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223105
|
4.3 |
MEDIUM
Network
|
dkd
|
direct_mail
|
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and e…
|
CWE-862
Missing Authorization
|
CVE-2019-16698
|
2024-11-21 13:31 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223106
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17223
|
2024-11-21 13:31 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223107
|
7.8 |
HIGH
Local
|
bmc
|
patrol_agent
|
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the on…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17044
|
2024-11-21 13:31 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223108
|
7.8 |
HIGH
Local
|
bmc
|
patrol_agent
|
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" u…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17043
|
2024-11-21 13:31 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223109
|
6.1 |
MEDIUM
Network
|
genesys
|
eservices_chat
|
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2019-17176
|
2024-11-21 13:31 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223110
|
9.8 |
CRITICAL
Network
|
connect2id apache oracle
|
nimbus_jose\+jwt hadoop solaris_cluster weblogic_server peoplesoft_enterprise_peopletools enterprise_manager_base_platform primavera_gateway data_integrator communications_pri…
|
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authenti…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-17195
|
2024-11-21 13:31 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|