๐จ CVE-2019-16066
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.
๐@cveNotify
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.
๐@cveNotify
๐จ CVE-2019-16067
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.
๐@cveNotify
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.
๐@cveNotify
๐จ CVE-2019-16070
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through web application form inputs.
๐@cveNotify
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through web application form inputs.
๐@cveNotify
๐จ CVE-2019-16337
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
๐@cveNotify
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
๐@cveNotify
๐จ CVE-2019-16338
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
๐@cveNotify
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
๐@cveNotify
๐จ CVE-2019-16375
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent composes an answer to the original article.
๐@cveNotify
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent composes an answer to the original article.
๐@cveNotify
OTRS
((OTRS)) Community Edition
((OTRS)) Community Edition is an open source help desk and ticketing system.
๐จ CVE-2019-20513
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
๐@cveNotify
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
๐@cveNotify
Invicti
NS-19-014 | OpenEdx vulnerable to Reflected Cross-site Scripting | Invicti
Advisory about Reflected Cross-site Scripting Vulnerabilities in OpenEdx, identified with Invicti web vulnerability scanner.
๐จ CVE-2019-20525
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
๐@cveNotify
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
๐@cveNotify
Invicti
NS-19-015 | Openfire vulnerable to Reflected Cross-site Scripting | Invicti
Advisory about Reflected Cross-site Scripting Vulnerabilities in Openfire, identified with Invicti web vulnerability scanner.
๐จ CVE-2019-20526
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
๐@cveNotify
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
๐@cveNotify
Invicti
NS-19-015 | Openfire vulnerable to Reflected Cross-site Scripting | Invicti
Advisory about Reflected Cross-site Scripting Vulnerabilities in Openfire, identified with Invicti web vulnerability scanner.
๐จ CVE-2020-5267
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
๐@cveNotify
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
๐@cveNotify
GitHub
Fix possible XSS vector in JS escape helper ยท rails/rails@033a738
This commit escapes dollar signs and backticks to prevent JS XSS issues
when using the `j` or `javascript_escape` helper
CVE-2020-5267
when using the `j` or `javascript_escape` helper
CVE-2020-5267
๐จ CVE-2019-20514
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
๐@cveNotify
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
๐@cveNotify
Invicti
NS-19-017 | ERPNext vulnerable to Cross-site Scripting | Invicti
Advisory about Cross-site Scripting Vulnerabilities in ERPNext, identified with Invicti web vulnerability scanner.
๐จ CVE-2019-20515
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
๐@cveNotify
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
๐@cveNotify
Invicti
NS-19-017 | ERPNext vulnerable to Cross-site Scripting | Invicti
Advisory about Cross-site Scripting Vulnerabilities in ERPNext, identified with Invicti web vulnerability scanner.
๐จ CVE-2019-20516
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
๐@cveNotify
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
๐@cveNotify
Invicti
NS-19-017 | ERPNext vulnerable to Cross-site Scripting | Invicti
Advisory about Cross-site Scripting Vulnerabilities in ERPNext, identified with Invicti web vulnerability scanner.
๐จ CVE-2019-20517
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
๐@cveNotify
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
๐@cveNotify
Invicti
NS-19-017 | ERPNext vulnerable to Cross-site Scripting | Invicti
Advisory about Cross-site Scripting Vulnerabilities in ERPNext, identified with Invicti web vulnerability scanner.
๐จ CVE-2019-20518
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
๐@cveNotify
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
๐@cveNotify
Invicti
NS-19-017 | ERPNext vulnerable to Cross-site Scripting | Invicti
Advisory about Cross-site Scripting Vulnerabilities in ERPNext, identified with Invicti web vulnerability scanner.
๐จ CVE-2020-7006
Systech Corporation NDS-5000 Terminal Server, NDS/5008 (8 Port, RJ45), firmware Version 02D.30. Successful exploitation of this vulnerability could allow information disclosure, limit system availability, and may allow remote code execution.
๐@cveNotify
Systech Corporation NDS-5000 Terminal Server, NDS/5008 (8 Port, RJ45), firmware Version 02D.30. Successful exploitation of this vulnerability could allow information disclosure, limit system availability, and may allow remote code execution.
๐@cveNotify
๐จ CVE-2019-16529
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.
๐@cveNotify
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.
๐@cveNotify
๐จ CVE-2020-10669
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version.
๐@cveNotify
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version.
๐@cveNotify
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
๐จ CVE-2019-16071
Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is possible for a low-privileged user to perform all actions as an administrator by bypassing authorization controls and sending requests to the server in the context of an administrator.
๐@cveNotify
Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is possible for a low-privileged user to perform all actions as an administrator by bypassing authorization controls and sending requests to the server in the context of an administrator.
๐@cveNotify
๐จ CVE-2019-16072
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
๐@cveNotify
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
๐@cveNotify
๐จ CVE-2019-16108
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
๐@cveNotify
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
๐@cveNotify