|
213131
|
9.8 |
CRITICAL
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's arc…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-7731
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213132
|
5.7 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-7730
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213133
|
8.1 |
HIGH
Network
|
pmd_project
|
pmd
|
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when u…
|
CWE-611
XXE
|
CVE-2019-7722
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213134
|
7.5 |
HIGH
Network
|
nconsulting
|
nc-cms
|
lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-7721
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213135
|
9.8 |
CRITICAL
Network
|
taogogo
|
taocms
|
taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
|
CWE-94
Code Injection
|
CVE-2019-7720
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213136
|
9.8 |
CRITICAL
Network
|
nibbleblog
|
nibbleblog
|
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
|
CWE-94
Code Injection
|
CVE-2019-7719
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213137
|
8.1 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogets…
|
CWE-362
Race Condition
|
CVE-2019-7718
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213138
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-7704
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213139
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
In Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service via a …
|
CWE-416
Use After Free
|
CVE-2019-7703
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213140
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
A NULL pointer dereference was discovered in wasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to de…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-7702
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|