|
225431
|
6.1 |
MEDIUM
Network
|
mfscripts
|
yetishare
|
_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the fileIds parameter on the page, …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19733
|
2024-11-21 13:35 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225432
|
7.2 |
HIGH
Network
|
mfscripts
|
yetishare
|
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. Thi…
|
CWE-89
SQL Injection
|
CVE-2019-19732
|
2024-11-21 13:35 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225433
|
9.8 |
CRITICAL
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware
|
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2019-19781
|
2024-11-21 13:35 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225434
|
7.5 |
HIGH
Network
|
intelbras
|
iwr_3000n_firmware
|
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} s…
|
NVD-CWE-noinfo
|
CVE-2019-19996
|
2024-11-21 13:35 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225435
|
8.8 |
HIGH
Network
|
intelbras
|
iwr_3000n_firmware
|
A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.
|
CWE-352
Origin Validation Error
|
CVE-2019-19995
|
2024-11-21 13:35 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225436
|
8.8 |
HIGH
Network
|
artica
|
pandora_fms
|
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE…
|
CWE-863
Incorrect Authorization
|
CVE-2019-19681
|
2024-11-21 13:35 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225437
|
7.2 |
HIGH
Network
|
halo
|
halo
|
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-19999
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225438
|
7.5 |
HIGH
Network
|
xiuno
|
xiunobbs
|
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
|
CWE-611
XXE
|
CVE-2019-19998
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225439
|
5.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
|
CWE-862
Missing Authorization
|
CVE-2019-19985
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225440
|
6.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
|
CWE-863
Incorrect Authorization
|
CVE-2019-19984
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|