|
212751
|
7.0 |
HIGH
Local
|
lg
|
lha.sys
|
The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests an…
|
CWE-59
Link Following
|
CVE-2019-8372
|
2024-11-21 13:49 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212752
|
5.4 |
MEDIUM
Network
|
txjia
|
imcat
|
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8436
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212753
|
4.8 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8435
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212754
|
6.1 |
MEDIUM
Network
|
cmseasy
|
cmseasy
|
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8434
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212755
|
7.5 |
HIGH
Network
|
jtbc
|
jtbc_php
|
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-8433
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212756
|
6.1 |
MEDIUM
Network
|
cmseasy
|
cmseasy
|
In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8432
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212757
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8429
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212758
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
|
CWE-89
SQL Injection
|
CVE-2019-8428
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212759
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
|
CWE-78
OS Command
|
CVE-2019-8427
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212760
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8426
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|