|
211751
|
7.2 |
HIGH
Network
|
postgresql
|
postgresql
|
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's ope…
|
CWE-78
OS Command
|
CVE-2019-9193
|
2024-11-21 13:51 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211752
|
8.8 |
HIGH
Network
|
kakaocorp
|
kakaotalk
|
Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the message window. This affects KaKaoTalk windows version 2.7.5.2024 or lower.
|
NVD-CWE-noinfo
|
CVE-2019-9132
|
2024-11-21 13:51 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211753
|
5.4 |
MEDIUM
Network
|
online_lottery_php_readymade_script_project
|
online_lottery_php_readymade_script
|
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9605
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211754
|
8.8 |
HIGH
Network
|
online_lottery_php_readymade_script_project
|
online_lottery_php_readymade_script
|
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
|
CWE-352
Origin Validation Error
|
CVE-2019-9604
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211755
|
6.1 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9167
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211756
|
7.8 |
HIGH
Local
|
nagios
|
nagios_xi
|
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-9166
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211757
|
9.8 |
CRITICAL
Network
|
nagios
|
incident_manager
|
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2019-9204
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211758
|
9.8 |
CRITICAL
Network
|
nagios
|
incident_manager
|
Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
|
NVD-CWE-noinfo
|
CVE-2019-9203
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211759
|
8.8 |
HIGH
Network
|
nagios
|
incident_manager
|
Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
|
NVD-CWE-noinfo
|
CVE-2019-9202
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211760
|
9.8 |
CRITICAL
Network
|
nagios
|
nagios_xi
|
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
|
CWE-89
SQL Injection
|
CVE-2019-9165
|
2024-11-21 13:51 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|