|
223731
|
7.8 |
HIGH
Local
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privile…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19585
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223732
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the…
|
CWE-78
OS Command
|
CVE-2019-19509
|
2024-11-21 13:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223733
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19265
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223734
|
5.4 |
MEDIUM
Network
|
icewarp
|
mail_server
|
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19266
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223735
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-19314
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223736
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-19313
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223737
|
5.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private p…
|
NVD-CWE-noinfo
|
CVE-2019-19312
|
2024-11-21 13:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223738
|
4.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19310
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223739
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-19309
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223740
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19263
|
2024-11-21 13:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|