|
224921
|
6.1 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBE…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16665
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224922
|
4.8 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16664
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224923
|
5.4 |
MEDIUM
Network
|
digimute
|
ogma_cms
|
Ogma CMS 0.5 has XSS via creation of a new blog.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16661
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224924
|
8.8 |
HIGH
Network
|
joyplus_project
|
joyplus
|
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16660
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224925
|
8.8 |
HIGH
Network
|
tuzicms
|
tuzicms
|
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16659
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224926
|
8.8 |
HIGH
Network
|
tuzicms
|
tuzicms
|
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16658
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224927
|
6.1 |
MEDIUM
Network
|
tuzicms
|
tuzicms
|
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16657
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224928
|
9.8 |
CRITICAL
Network
|
joyplus_project
|
joyplus
|
joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.
|
NVD-CWE-noinfo
|
CVE-2019-16656
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224929
|
7.5 |
HIGH
Network
|
joyplus_project
|
joyplus
|
joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.
|
NVD-CWE-noinfo
|
CVE-2019-16655
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224930
|
8.6 |
HIGH
Network
|
embedthis
|
goahead
|
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sen…
|
CWE-94
Code Injection
|
CVE-2019-16645
|
2024-11-21 13:30 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|