|
218761
|
8.2 |
HIGH
Network
|
golang debian opensuse
|
go debian_linux leap
|
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recove…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6486
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218762
|
9.8 |
CRITICAL
Network
|
thinkcmf
|
thinkcmf
|
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code int…
|
CWE-94
Code Injection
|
CVE-2019-6713
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218763
|
7.2 |
HIGH
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6708
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218764
|
7.2 |
HIGH
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6707
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218765
|
7.5 |
HIGH
Network
|
lua canonical
|
lua ubuntu_linux
|
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have …
|
CWE-416
Use After Free
|
CVE-2019-6706
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218766
|
7.2 |
HIGH
Network
|
phpwind
|
phpwind
|
phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup database" option.
|
CWE-89
SQL Injection
|
CVE-2019-6691
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218767
|
8.8 |
HIGH
Network
|
creditease-sec
|
insight
|
An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-6510
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218768
|
8.8 |
HIGH
Network
|
creditease-sec
|
insight
|
An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-6509
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218769
|
8.8 |
HIGH
Network
|
creditease-sec
|
insight
|
An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-6508
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218770
|
8.8 |
HIGH
Network
|
creditease-sec
|
insight
|
An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-6507
|
2024-11-21 13:46 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|