Unknown · CVSS Not scored
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary script via setup.html in the web interface.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.
Published Mar 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SaltOS 3.1 r8126 contains a database download vulnerability.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
Published Mar 17, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system.
Published Mar 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders. In addition, the program installs a service called "KWSService" which runs as "Localsystem", this will allow any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a malicious one.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this server through named pipes. A user can initiate communication with the server by creating a named pipe and sending commands to achieve elevated privileges.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe attempts to enforce access control by adding an unprivileged user to the local Administrators group for a very short time to execute a single command. However, the user is left in that group if the command crashes, and there is also a race condition in all cases.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App Launcher (CAL) database, and potentially gain privileges by placing a Trojan horse program at an app pathname.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged users via the --system option.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with userName=admin in a cookie.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.
Published Mar 12, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
Published Mar 2, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Group configuration, (3) "Rule Name" field in the Access Control configuration, (4) "Service Name" in the Service Configuration, or (5) First Name or Last Name field in the Edit Account configuration.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/<number>/<filename>. Accessing the file once uploaded does not require authentication.
Published Mar 2, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
Published Mar 7, 2019 · Updated Aug 5, 2024
High · CVSS 7.8
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.
Published Mar 25, 2019 · Updated Aug 5, 2024
Medium · CVSS 5.5
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Published Mar 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
Published Mar 7, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions), Firmware variant Profinet IO for EN100 Ethernet module (All versions), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.82), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. A manual restart is required to recover the EN100 module functionality of the affected devices. Successful exploitation requires an attacker with network access to send multiple packets to the affected products or modules. As a precondition the IEC 61850-MMS communication needs to be activated on the affected products or modules. No user interaction or privileges are required to exploit the vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Published Mar 21, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.
Published Mar 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
Published Mar 2, 2020 · Updated Aug 5, 2024