|
212081
|
7.2 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting …
|
CWE-77
Command Injection
|
CVE-2019-9059
|
2024-11-21 13:50 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212082
|
7.2 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated o…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2019-9058
|
2024-11-21 13:50 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212083
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.
|
CWE-502 CWE-915
Deserialization of Untrusted Data Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2019-9057
|
2024-11-21 13:50 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212084
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer perm…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-9055
|
2024-11-21 13:50 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212085
|
8.1 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9053
|
2024-11-21 13:50 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212086
|
9.8 |
CRITICAL
Network
|
axtls_project
|
axtls
|
tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because the need_bytes value is mismanaged.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-8981
|
2024-11-21 13:50 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212087
|
5.9 |
MEDIUM
Network
|
blackberry
|
athoc
|
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary loca…
|
CWE-611
XXE
|
CVE-2019-8997
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212088
|
6.1 |
MEDIUM
Network
|
humhub
|
humhub
|
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in the filename is echo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9094
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212089
|
6.1 |
MEDIUM
Network
|
humhub
|
humhub
|
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename par…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9093
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212090
|
9.8 |
CRITICAL
Network
|
sqlitemanager
|
sqlitemanager
|
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
|
CWE-89
SQL Injection
|
CVE-2019-9083
|
2024-11-21 13:50 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|