Security Vulnerabilities
- CVEs Published In September 2019
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure&NTLM= URI.
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
eBrigade before 5.0 has evenements.php cid SQL Injection.
eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.