Total
2906 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-19180 | 1 Yunucms | 1 Yunucms | 2018-12-12 | 7.5 HIGH | 9.8 CRITICAL |
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php. | |||||
CVE-2018-19220 | 1 Laobancms | 1 Laobancms | 2018-12-11 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI. | |||||
CVE-2017-11459 | 1 Sap | 1 Trex | 2018-12-10 | 7.5 HIGH | 9.8 CRITICAL |
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592. | |||||
CVE-2015-1311 | 1 Sap | 1 Hana Extend Application Services | 2018-12-10 | 10.0 HIGH | N/A |
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2014-8660 | 1 Sap | 1 Document Management Services | 2018-12-10 | 7.2 HIGH | N/A |
SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors. | |||||
CVE-2018-7633 | 1 Adbglobal | 1 Epicentro | 2018-12-10 | 7.5 HIGH | 9.8 CRITICAL |
Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request. | |||||
CVE-2018-18835 | 1 Doccms | 1 Doccms | 2018-12-06 | 7.5 HIGH | 9.8 CRITICAL |
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file. | |||||
CVE-2018-18892 | 1 1234n | 1 Minicms | 2018-12-03 | 7.5 HIGH | 9.8 CRITICAL |
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | |||||
CVE-2018-18426 | 1 S-cms | 1 S-cms | 2018-12-03 | 9.0 HIGH | 8.8 HIGH |
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter. | |||||
CVE-2018-18461 | 1 Kibokolabs | 1 Arigato Autoresponder And Newsletter | 2018-11-30 | 7.5 HIGH | 9.8 CRITICAL |
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php. | |||||
CVE-2018-18083 | 1 Comsenz | 1 Duomicms | 2018-11-29 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing. | |||||
CVE-2015-9272 | 1 Videowhisper | 1 Video Presentation | 2018-11-23 | 7.5 HIGH | 9.8 CRITICAL |
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code. | |||||
CVE-2013-2134 | 1 Apache | 1 Struts | 2018-11-23 | 9.3 HIGH | N/A |
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135. | |||||
CVE-2013-2135 | 1 Apache | 1 Struts | 2018-11-23 | 9.3 HIGH | N/A |
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice. | |||||
CVE-2018-0674 | 1 Hibara | 1 Attachecase | 2018-11-20 | 6.8 MEDIUM | 7.8 HIGH |
AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors. | |||||
CVE-2018-0675 | 1 Hibara | 1 Attachecase | 2018-11-20 | 6.8 MEDIUM | 7.8 HIGH |
AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors. | |||||
CVE-2018-17126 | 1 Chshcms | 1 Cscms | 2018-11-19 | 7.5 HIGH | 9.8 CRITICAL |
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php. | |||||
CVE-2018-15886 | 1 Monstra | 1 Monstra | 2018-11-14 | 6.5 MEDIUM | 7.2 HIGH |
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP code by placing this code after a <?php substring. | |||||
CVE-2018-16604 | 1 Nibbleblog | 1 Nibbleblog | 2018-11-14 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}"). | |||||
CVE-2018-16343 | 1 Seacms | 1 Seacms | 2018-11-13 | 6.5 MEDIUM | 7.2 HIGH |
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS. |