|
222111
|
8.8 |
HIGH
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17119
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222112
|
8.8 |
HIGH
Network
|
wikidsystems
|
2fa_enterprise_server
|
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2…
|
CWE-352
Origin Validation Error
|
CVE-2019-17118
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222113
|
8.8 |
HIGH
Network
|
wikidsystems
|
2fa_enterprise_server
|
A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key paramete…
|
CWE-89
SQL Injection
|
CVE-2019-17117
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222114
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17116
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222115
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17115
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222116
|
6.1 |
MEDIUM
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userP…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17114
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222117
|
8.8 |
HIGH
Network
|
wikidsystems
|
two_factor_authentication_enterprise_server
|
WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, u…
|
CWE-89
SQL Injection
|
CVE-2019-16917
|
2024-11-21 13:31 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222118
|
9.8 |
CRITICAL
Network
|
slub-dresden
|
slub_events
|
The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execut…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16700
|
2024-11-21 13:31 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222119
|
9.8 |
CRITICAL
Network
|
sr_freecap_project
|
sr_freecap
|
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Cod…
|
CWE-20
Improper Input Validation
|
CVE-2019-16699
|
2024-11-21 13:31 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222120
|
4.3 |
MEDIUM
Network
|
dkd
|
direct_mail
|
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and e…
|
CWE-862
Missing Authorization
|
CVE-2019-16698
|
2024-11-21 13:31 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|