|
212631
|
6.1 |
MEDIUM
Network
|
vfront
|
vfront
|
VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9839
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212632
|
6.1 |
MEDIUM
Network
|
vfront
|
vfront
|
VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9838
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212633
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-9824
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212634
|
4.3 |
MEDIUM
Network
|
otrs
|
otrs
|
An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an agent or a customer user can use the search result screens to disclose informa…
|
CWE-200
Information Exposure
|
CVE-2019-9753
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212635
|
8.8 |
HIGH
Network
|
hgiga
|
msr45_isherlock-base msr45_isherlock-useradmin msr45_isherlock-sysinfo msr45_isherlock-user msr35_isherlock-base msr35_isherlock-useradmin msr35_isherlock-sysinfo msr35_isherlock…
|
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_a…
|
CWE-352
Origin Validation Error
|
CVE-2019-9883
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212636
|
8.8 |
HIGH
Network
|
hgiga
|
msr45_isherlock-base msr45_isherlock-useradmin msr45_isherlock-sysinfo msr45_isherlock-user msr35_isherlock-base msr35_isherlock-useradmin msr35_isherlock-sysinfo msr35_isherlock…
|
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&l…
|
CWE-352
Origin Validation Error
|
CVE-2019-9882
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212637
|
9.8 |
CRITICAL
Network
|
nuuo
|
network_video_recorder_firmware
|
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
|
CWE-78
OS Command
|
CVE-2019-9653
|
2024-11-21 13:52 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212638
|
9.8 |
CRITICAL
Network
|
tldp
|
advanced_bash-scripting_guide
|
The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, v…
|
CWE-94
Code Injection
|
CVE-2019-9891
|
2024-11-21 13:52 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212639
|
8.8 |
HIGH
Network
|
sitecore
|
cms
|
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parame…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-9875
|
2024-11-21 13:52 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212640
|
9.8 |
CRITICAL
Network
|
sitecore
|
experience_platform cms
|
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrar…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-9874
|
2024-11-21 13:52 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|