|
212911
|
9.8 |
CRITICAL
Network
|
pytroll
|
donfig
|
An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execution.
|
CWE-77
Command Injection
|
CVE-2019-7537
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212912
|
6.5 |
MEDIUM
Network
|
woocommerce
|
paypal_checkout_payment_gateway
|
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchas…
|
NVD-CWE-noinfo
|
CVE-2019-7441
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212913
|
6.5 |
MEDIUM
Network
|
jio
|
jiofi_4g_m2s_firmware
|
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).
|
CWE-352
Origin Validation Error
|
CVE-2019-7440
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212914
|
6.5 |
MEDIUM
Adjacent
|
jio
|
jiofi_4g_m2s_firmware
|
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
|
NVD-CWE-noinfo
|
CVE-2019-7439
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212915
|
6.1 |
MEDIUM
Network
|
jio
|
jiofi_4g_m2s_firmware
|
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7438
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212916
|
6.1 |
MEDIUM
Network
|
opensource_classified_ads_script_project
|
opensource_classified_ads_script
|
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7437
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212917
|
6.5 |
MEDIUM
Network
|
opensource_classified_ads_script_project
|
opensource_classified_ads_script
|
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.
|
CWE-200
Information Exposure
|
CVE-2019-7436
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212918
|
5.3 |
MEDIUM
Network
|
opensource_classified_ads_script_project
|
opensource_classified_ads_script
|
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7435
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212919
|
6.5 |
MEDIUM
Network
|
rental_bike_script_project
|
rental_bike_script
|
PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.
|
CWE-200
Information Exposure
|
CVE-2019-7434
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212920
|
8.8 |
HIGH
Network
|
rental_bike_script_project
|
rental_bike_script
|
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
|
CWE-352
Origin Validation Error
|
CVE-2019-7433
|
2024-11-21 13:48 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|