|
213721
|
5.3 |
MEDIUM
Network
|
cab_booking_script_project
|
cab_booking_script
|
PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file.
|
CWE-22
Path Traversal
|
CVE-2019-9064
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213722
|
6.5 |
MEDIUM
Network
|
auction_website_script_project
|
auction_website_script
|
PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount.
|
NVD-CWE-noinfo
|
CVE-2019-9063
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213723
|
8.0 |
HIGH
Network
|
phpscriptsmall
|
online_food_ordering_script
|
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-9062
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213724
|
9.8 |
CRITICAL
Network
|
fizzday
|
gorose
|
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
|
CWE-89
SQL Injection
|
CVE-2019-9047
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213725
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9052
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213726
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9051
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213727
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9050
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213728
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9049
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213729
|
6.5 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-9048
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213730
|
7.2 |
HIGH
Network
|
sitemagic
|
sitemagic_cms
|
An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can only occur if the ad…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9042
|
2024-11-21 13:50 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|