|
214201
|
6.1 |
MEDIUM
Network
|
cmseasy
|
cmseasy
|
In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8432
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214202
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8429
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214203
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
|
CWE-89
SQL Injection
|
CVE-2019-8428
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214204
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
|
CWE-78
OS Command
|
CVE-2019-8427
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214205
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8426
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214206
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8425
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214207
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8424
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214208
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8423
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214209
|
7.2 |
HIGH
Network
|
pbootcms
|
pbootcms
|
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php.
|
CWE-89
SQL Injection
|
CVE-2019-8422
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214210
|
7.2 |
HIGH
Network
|
bagesoft
|
bagecms
|
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8421
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|