Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In July 2019
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-07-10
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.
CVSS Score
8.8
EPSS Score
0.003
Published
2019-07-10
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-07-10
A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.
CVSS Score
6.5
EPSS Score
0.001
Published
2019-07-10
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
CVSS Score
5.9
EPSS Score
0.005
Published
2019-07-10
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.
CVSS Score
5.3
EPSS Score
0.665
Published
2019-07-10
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance
CVSS Score
9.8
EPSS Score
0.188
Published
2019-07-10
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance
CVSS Score
9.8
EPSS Score
0.048
Published
2019-07-10
Nagios XI before 5.5.4 has XSS in the auto login admin management page.
CVSS Score
4.8
EPSS Score
0.032
Published
2019-07-10
Helpy before 2.2.0 allows agents to edit admins.
CVSS Score
8.8
EPSS Score
0.004
Published
2019-07-10


Contact Us

Shodan ® - All rights reserved