|
222251
|
7.5 |
HIGH
Network
|
spin-rs_project
|
spin-rs
|
An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclus…
|
CWE-662
Improper Synchronization
|
CVE-2019-16137
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222252
|
6.5 |
MEDIUM
Network
|
weaver
|
eteams_oa
|
An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Spec…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-16133
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222253
|
6.5 |
MEDIUM
Network
|
phpok
|
oklite
|
An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.
|
CWE-22
Path Traversal
|
CVE-2019-16132
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222254
|
8.8 |
HIGH
Network
|
phpok
|
oklite
|
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16131
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222255
|
6.1 |
MEDIUM
Network
|
hgw168cc
|
yii-cms
|
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16130
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222256
|
6.1 |
MEDIUM
Network
|
getgrav
|
grav_cms
|
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16126
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222257
|
9.8 |
CRITICAL
Network
|
jobberbase
|
jobberbase
|
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-16125
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222258
|
9.8 |
CRITICAL
Network
|
youphptube
|
youphptube
|
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
|
CWE-862
Missing Authorization
|
CVE-2019-16124
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222259
|
7.5 |
HIGH
Network
|
kartatopia
|
piluscart
|
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
|
CWE-22
Path Traversal
|
CVE-2019-16123
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222260
|
8.8 |
HIGH
Network
|
tri
|
event_tickets
|
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-16120
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|