LiveActive security incident?Get immediate response
CVE archive

March 2018

Browse CVE records published in March 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1325 matching CVEs · Page 19 of 27.

Unknown · CVSS Not scored

CVE-2018-8966: An issue was discovered in zzcms 8.2.

An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

Published Mar 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8970: The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does...

The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.

Published Mar 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8965: An issue was discovered in zzcms 8.2.

An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

Published Mar 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8969: An issue was discovered in zzcms 8.2.

An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

Published Mar 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8908: An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5.

An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.

Published Mar 31, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8937: An issue was discovered in Open-AudIT Professional 2.1.

An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.

Published Mar 26, 2018 · Updated Aug 5, 2024