CVE-2018-16356: An issue was discovered in PbootCMS.
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
Published Mar 2, 2020 · Updated Aug 5, 2024
Browse CVE records published in March 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 1325 matching CVEs · Page 17 of 27.
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
Published Mar 2, 2020 · Updated Aug 5, 2024
PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restriction to alter or edit unauthorized files via unspecified vectors.
Published Mar 27, 2019 · Updated Aug 5, 2024
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
Published Mar 17, 2019 · Updated Aug 5, 2024
An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending a malicious request to admin-ajax.php.
Published Mar 17, 2019 · Updated Aug 5, 2024
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
Published Mar 29, 2019 · Updated Aug 5, 2024
EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
Published Mar 2, 2020 · Updated Aug 5, 2024
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image file.
Published Mar 26, 2019 · Updated Aug 5, 2024
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.
Published Mar 26, 2019 · Updated Aug 5, 2024
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d via a crafted image file.
Published Mar 26, 2019 · Updated Aug 5, 2024
FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a via a crafted image file.
Published Mar 26, 2019 · Updated Aug 5, 2024
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.
Published Mar 26, 2019 · Updated Aug 5, 2024
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
Published Mar 2, 2020 · Updated Aug 5, 2024
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
Published Mar 25, 2019 · Updated Aug 5, 2024
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
Published Mar 27, 2019 · Updated Aug 5, 2024
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.
Published Mar 17, 2019 · Updated Aug 5, 2024
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running the Five9 SoftPhone(issue 1 of 2).
Published Mar 15, 2019 · Updated Aug 5, 2024
YSoft SafeQ Server 6 allows a replay attack.
Published Mar 19, 2019 · Updated Aug 5, 2024
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
Published Mar 15, 2019 · Updated Aug 5, 2024
WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation of user-supplied data, which may result in a read past the end of an allocated object.
Published Mar 27, 2019 · Updated Aug 5, 2024
Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwrite kernel memory due to improper validation of the ring buffer read pointer. The Samsung ID is SVE-2018-12029.
Published Mar 15, 2019 · Updated Aug 5, 2024
In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.
Published Mar 18, 2019 · Updated Aug 5, 2024
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
Published Mar 17, 2019 · Updated Aug 5, 2024
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Published Mar 7, 2019 · Updated Aug 5, 2024
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
Published Mar 10, 2020 · Updated Aug 5, 2024
An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html.
Published Mar 7, 2019 · Updated Aug 5, 2024
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
Published Mar 17, 2019 · Updated Aug 5, 2024
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.
Published Mar 2, 2020 · Updated Aug 5, 2024
A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14), SICAM A8000 CP-8050 (All versions < V2.00). Specially crafted network packets sent to port 80/TCP or 443/TCP could allow an unauthenticated remote attacker to cause a Denial-of-Service condition of the web server. The security vulnerability could be exploited by an attacker with network access to the affected systems on port 80/TCP or 443/TCP. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the web server. A system reboot is required to recover the web service of the device. At the time of advisory update, exploit code for this security vulnerability is public.
Published Mar 21, 2019 · Updated Aug 5, 2024
OX App Suite 7.8.4 and earlier allows SSRF.
Published Mar 17, 2019 · Updated Aug 5, 2024
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
Published Mar 17, 2019 · Updated Aug 5, 2024
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
Published Mar 16, 2020 · Updated Aug 5, 2024
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
Published Mar 16, 2020 · Updated Aug 5, 2024
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.
Published Mar 17, 2019 · Updated Aug 5, 2024
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
Published Mar 17, 2019 · Updated Aug 5, 2024
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs, clients can circumvent authentication and get access to the broker by using the malformed username. In particular, a blank line will be treated as a valid empty username. Other security measures are unaffected. Users who have only used the mosquitto_passwd utility to create and modify their password files are unaffected by this vulnerability.
Published Mar 27, 2019 · Updated Aug 5, 2024
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that all access is denied, which is not a useful configuration but is not unexpected.
Published Mar 27, 2019 · Updated Aug 5, 2024
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.
Published Mar 27, 2019 · Updated Aug 5, 2024
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
Published Mar 27, 2019 · Updated Aug 5, 2024
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published Mar 27, 2019 · Updated Aug 5, 2024
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
Published Mar 27, 2019 · Updated Aug 5, 2024
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published Mar 27, 2019 · Updated Aug 5, 2024
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published Mar 27, 2019 · Updated Aug 5, 2024
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
Published Mar 27, 2019 · Updated Aug 5, 2024
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
Published Mar 27, 2019 · Updated Aug 5, 2024
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
Published Mar 17, 2019 · Updated Aug 5, 2024
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
Published Mar 17, 2019 · Updated Aug 5, 2024
Possible double free issue in WLAN due to lack of checking memory free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, MDM9640, SDA660, SDM636, SDM660, SDX20
Published Mar 5, 2020 · Updated Aug 5, 2024
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.
Published Mar 18, 2019 · Updated Aug 5, 2024
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
Published Mar 18, 2019 · Updated Aug 5, 2024
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be able to provide their own TLS certificate for ingress.
Published Mar 17, 2019 · Updated Aug 5, 2024