|
219621
|
6.1 |
MEDIUM
Network
|
sitracker
|
support_incident_tracker
|
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20223
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219622
|
6.1 |
MEDIUM
Network
|
sitracker
|
support_incident_tracker
|
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20222
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219623
|
6.1 |
MEDIUM
Network
|
sitracker
|
support_incident_tracker
|
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20221
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219624
|
6.1 |
MEDIUM
Network
|
sitracker
|
support_incident_tracker
|
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20220
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219625
|
7.5 |
HIGH
Network
|
sqlite debian canonical oracle
|
sqlite debian_linux ubuntu_linux mysql_workbench
|
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
|
NVD-CWE-Other CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-20218
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219626
|
7.5 |
HIGH
Network
|
dlink
|
dir-859_firmware dir-822_firmware dir-823_firmware dir-865l_firmware dir-868l_firmware dir-869_firmware dir-880l_firmware dir-890l_firmware dir-890r_firmware dir-885l_firmw…
|
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
|
CWE-74 CWE-863
Injection Incorrect Authorization
|
CVE-2019-20213
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219627
|
5.4 |
MEDIUM
Network
|
postieplugin
|
postie
|
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20204
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219628
|
5.3 |
MEDIUM
Network
|
postieplugin
|
postie
|
The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-20203
|
2024-11-21 13:38 |
2020-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219629
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block that was not allocated, leading to an invalid free and segmentation fault.
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2019-20202
|
2024-11-21 13:38 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219630
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.
|
CWE-400 CWE-835
Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-20201
|
2024-11-21 13:38 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|