|
223221
|
7.2 |
HIGH
Network
|
ilch
|
ilch_cms
|
Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17046
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223222
|
4.8 |
MEDIUM
Network
|
ilch
|
ilch_cms
|
Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17045
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223223
|
9.8 |
CRITICAL
Network
|
rsyslog
|
rsyslog
|
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17040
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223224
|
9.8 |
CRITICAL
Network
|
idcos
|
cloudboot
|
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.
|
CWE-89
SQL Injection
|
CVE-2019-16999
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223225
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
|
CWE-89
SQL Injection
|
CVE-2019-16997
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223226
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-16996
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223227
|
4.7 |
MEDIUM
Local
|
linux redhat opensuse
|
linux_kernel enterprise_linux leap
|
In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-16994
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223228
|
8.8 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16745
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223229
|
8.8 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade before 5.0 has evenements.php cid SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16744
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223230
|
8.8 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16743
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|