|
219141
|
6.1 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2019-4744
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219142
|
4.3 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-4743
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219143
|
6.1 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-4742
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219144
|
4.3 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website …
|
CWE-352
Origin Validation Error
|
CVE-2019-4736
|
2024-11-21 13:44 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219145
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace pro…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-5469
|
2024-11-21 13:44 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219146
|
9.1 |
CRITICAL
Network
|
wago
|
pfc_200_firmware pfc_100_firmware
|
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware versi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5080
|
2024-11-21 13:44 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219147
|
9.8 |
CRITICAL
Network
|
wago
|
pfc_200_firmware pfc_100_firmware
|
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware ver…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5079
|
2024-11-21 13:44 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219148
|
9.1 |
CRITICAL
Network
|
wago
|
pfc_200_firmware pfc_100_firmware
|
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware versio…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5078
|
2024-11-21 13:44 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219149
|
9.8 |
CRITICAL
Network
|
wago
|
pfc_200_firmware pfc_100_firmware
|
An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware versio…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5075
|
2024-11-21 13:44 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219150
|
5.3 |
MEDIUM
Network
|
wago
|
pfc_200_firmware pfc_100_firmware
|
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware ver…
|
CWE-200
Information Exposure
|
CVE-2019-5073
|
2024-11-21 13:44 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|