|
222831
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17419
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222832
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
|
CWE-89
SQL Injection
|
CVE-2019-17418
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222833
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17417
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222834
|
9.8 |
CRITICAL
Network
|
upredsun
|
file_sharing_wizard
|
A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a simil…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17415
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222835
|
7.5 |
HIGH
Network
|
vino_project
|
vino
|
tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.
|
NVD-CWE-noinfo
|
CVE-2019-17414
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222836
|
8.8 |
HIGH
Network
|
citrix
|
application_delivery_management
|
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-17366
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222837
|
7.8 |
HIGH
Local
|
nixos
|
nix
|
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17365
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222838
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17402
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222839
|
3.3 |
LOW
Local
|
liblnk_project
|
liblnk
|
libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue th…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17401
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222840
|
9.8 |
CRITICAL
Network
|
joomlashack
|
shack_forms_pro
|
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
|
CWE-22
Path Traversal
|
CVE-2019-17399
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|