|
222751
|
9.8 |
CRITICAL
Network
|
phpipam
|
phpipam
|
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
|
CWE-89
SQL Injection
|
CVE-2019-16692
|
2024-11-21 13:30 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222752
|
4.7 |
MEDIUM
Network
|
traveloka
|
traveloka
|
The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16681
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222753
|
4.3 |
MEDIUM
Network
|
gnome redhat debian canonical
|
file-roller enterprise_linux debian_linux ubuntu_linux
|
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
|
CWE-22
Path Traversal
|
CVE-2019-16680
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222754
|
4.9 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
|
CWE-22
Path Traversal
|
CVE-2019-16679
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222755
|
6.5 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
|
CWE-352
Origin Validation Error
|
CVE-2019-16678
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222756
|
6.5 |
MEDIUM
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16677
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222757
|
5.3 |
MEDIUM
Network
|
pagekit
|
pagekit
|
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumera…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16669
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222758
|
6.1 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBE…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16665
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222759
|
4.8 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16664
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222760
|
5.4 |
MEDIUM
Network
|
digimute
|
ogma_cms
|
Ogma CMS 0.5 has XSS via creation of a new blog.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16661
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|