Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2019
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.
CVSS Score
9.8
EPSS Score
0.109
Published
2019-09-18
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
CVSS Score
8.8
EPSS Score
0.003
Published
2019-09-18
The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter.
CVSS Score
6.1
EPSS Score
0.009
Published
2019-09-18
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
CVSS Score
9.8
EPSS Score
0.008
Published
2019-09-18
The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing of future messages.
CVSS Score
6.5
EPSS Score
0.005
Published
2019-09-18
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server using the default local uploads backend, the attack is only effective against browsers lacking support for Content-Security-Policy such as Internet Explorer 11. On a Zulip server using the S3 uploads backend, the attack is confined to the origin of the configured S3 uploads hostname and cannot reach the Zulip server itself.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-09-18
GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-09-17
GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source code.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-09-17
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.
CVSS Score
9.8
EPSS Score
0.494
Published
2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
CVSS Score
6.5
EPSS Score
0.01
Published
2019-09-17


Contact Us

Shodan ® - All rights reserved