[webapps] MACCMS 10 – Cross-Site Request Forgery (Add User)
libpff 2018-04-28 Information Disclosure
The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file.
libmobi 0.3 Information Disclosure
The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file. The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file. […]
libfsntfs 20180420 Information Disclosure
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c […]
OX App Suite 7.8.4 XSS / Privilege Management / SSRF / Traversal
OX App Suite versions 7.8.4 and below suffer from cross site scripting, improper privilege management, content spoofing, server-side request forgery, and path traversal vulnerabilities.
XiongMai uc-httpd 1.0.0 Buffer Overflow
XiongMai uc-httpd version 1.0.0 suffers from a buffer overflow vulnerability.
WebCTRL Out-Of-Band XML Injection
WebCTRL suffers from an out-of-band XML external entity injection vulnerability.
SensioLabs Symfony 3.3.6 Cross Site Scripting
SensioLabs Symfony version 3.3.6 suffers from a cross site scripting vulnerability.
Schools Alert Management Script SQL Injection
Schools Alert Management Script suffers from a remote SQL injection vulnerability.