|
213641
|
7.5 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This…
|
CWE-22
Path Traversal
|
CVE-2019-7235
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213642
|
9.1 |
CRITICAL
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents…
|
CWE-22
Path Traversal
|
CVE-2019-7234
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213643
|
8.8 |
HIGH
Network
|
libdoc_project
|
libdoc
|
In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-7233
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213644
|
4.8 |
MEDIUM
Network
|
croogo
|
croogo
|
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7173
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213645
|
6.1 |
MEDIUM
Network
|
atutor
|
atutor
|
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7172
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213646
|
4.8 |
MEDIUM
Network
|
croogo
|
croogo
|
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/blocks/blocks/edit/8.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7171
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213647
|
4.8 |
MEDIUM
Network
|
croogo
|
croogo
|
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7170
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213648
|
4.8 |
MEDIUM
Network
|
croogo
|
croogo
|
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/menus/menus/edit/3.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7169
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213649
|
4.8 |
MEDIUM
Network
|
croogo
|
croogo
|
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7168
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213650
|
9.8 |
CRITICAL
Network
|
idreamsoft
|
icms
|
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.p…
|
CWE-22
Path Traversal
|
CVE-2019-7160
|
2024-11-21 13:47 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|