|
213671
|
6.5 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
|
CWE-352
Origin Validation Error
|
CVE-2019-9603
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213672
|
7.5 |
HIGH
Network
|
apowersoft
|
apowermanager
|
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestAuthorization requests.
|
NVD-CWE-noinfo
|
CVE-2019-9601
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213673
|
7.5 |
HIGH
Network
|
theolivetree
|
ftp_server
|
The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts a…
|
NVD-CWE-noinfo
|
CVE-2019-9600
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213674
|
7.5 |
HIGH
Network
|
airdroid
|
airdroid
|
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.
|
NVD-CWE-noinfo
|
CVE-2019-9599
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213675
|
6.1 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9595
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213676
|
9.8 |
CRITICAL
Network
|
bluecms_project
|
bluecms
|
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
|
CWE-89
SQL Injection
|
CVE-2019-9594
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213677
|
6.1 |
MEDIUM
Network
|
mitel
|
connect_onsite
|
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9593
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213678
|
6.1 |
MEDIUM
Network
|
mitel
|
connect_onsite
|
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9592
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213679
|
6.1 |
MEDIUM
Network
|
mitel
|
connect_onsite
|
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9591
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213680
|
7.5 |
HIGH
Network
|
tengcon
|
t-920_plc_firmware
|
An issue was discovered on TENGCONTROL T-920 PLC v5.5 devices. It allows remote attackers to cause a denial of service (persistent failure mode) by sending a series of \x19\xb2\x00\x00\x00\x06\x43\x0…
|
NVD-CWE-noinfo
|
CVE-2019-9590
|
2024-11-21 13:51 |
2019-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|