|
222061
|
8.8 |
HIGH
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2019-17431
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222062
|
6.1 |
MEDIUM
Network
|
eyoucms
|
eyoucms
|
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17430
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222063
|
9.8 |
CRITICAL
Network
|
adhouma_cms_project
|
adhouma_cms
|
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17429
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222064
|
6.1 |
MEDIUM
Network
|
redmine
|
redmine
|
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17427
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222065
|
9.1 |
CRITICAL
Network
|
mongoosejs
|
mongoose
|
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" …
|
NVD-CWE-noinfo
|
CVE-2019-17426
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222066
|
5.3 |
MEDIUM
Network
|
suricata-ids oisf
|
suricata libhtp
|
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
|
CWE-459
Incomplete Cleanup
|
CVE-2019-17420
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222067
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17419
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222068
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
|
CWE-89
SQL Injection
|
CVE-2019-17418
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222069
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17417
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222070
|
9.8 |
CRITICAL
Network
|
upredsun
|
file_sharing_wizard
|
A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a simil…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17415
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|