|
213231
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or outp…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7331
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213232
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'show' parameter value in the view frame (frame.php)…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7330
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213233
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the form action on multiple views utilizes $_SERVER['PHP_SELF'] insecurely, mishandling any arbitrary input appended to th…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7329
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213234
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7328
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213235
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7327
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213236
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Host' parameter value in the view console (cons…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7326
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213237
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtrat…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7325
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213238
|
6.1 |
MEDIUM
Network
|
kanboard
|
kanboard
|
app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7324
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213239
|
7.5 |
HIGH
Network
|
logmx
|
logmx
|
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan hor…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-7323
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213240
|
5.3 |
MEDIUM
Network
|
libpng debian canonical oracle hpe hp mozilla opensuse netapp redhat
|
libpng debian_linux ubuntu_linux jdk java_se mysql hyperion_infrastructure_technology xp7_command_view_advanced_edition_suite xp7_command_view firefox thunderbird lea…
|
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
|
CWE-416
Use After Free
|
CVE-2019-7317
|
2024-11-21 13:48 |
2019-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|