|
221961
|
7.2 |
HIGH
Network
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overw…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-19020
|
2024-11-21 13:34 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221962
|
7.5 |
HIGH
Network
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix downlo…
|
CWE-346
Origin Validation Error
|
CVE-2019-19019
|
2024-11-21 13:34 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221963
|
2.7 |
LOW
Network
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web appl…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2019-19018
|
2024-11-21 13:34 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221964
|
8.1 |
HIGH
Network
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system.
|
CWE-362 CWE-798
Race Condition Use of Hard-coded Credentials
|
CVE-2019-19017
|
2024-11-21 13:34 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221965
|
7.5 |
HIGH
Network
|
titanhq
|
webtitan
|
An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This co…
|
CWE-89
SQL Injection
|
CVE-2019-19016
|
2024-11-21 13:34 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221966
|
9.8 |
CRITICAL
Network
|
maleck
|
image_uploader_and_browser_for_ckeditor
|
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
|
CWE-94
Code Injection
|
CVE-2019-19502
|
2024-11-21 13:34 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221967
|
9.8 |
CRITICAL
Network
|
napc
|
xinet_elegant_6_asset_library
|
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
|
CWE-89
SQL Injection
|
CVE-2019-19245
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221968
|
5.4 |
MEDIUM
Network
|
alfresco
|
alfresco
|
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19496
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221969
|
5.4 |
MEDIUM
Network
|
kentico
|
kentico
|
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
|
CWE-434 CWE-706
Unrestricted Upload of File with Dangerous Type Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-19493
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221970
|
6.5 |
MEDIUM
Network
|
teamviewer
|
teamviewer
|
An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendor states that it was later fixed.) Upon login, every communication is saved wit…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2019-19362
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|