Show filters
341 Total Results
Displaying 101-110 of 341
Sort by:
Attacker Value
Unknown
CVE-2018-7510
Disclosure Date: June 06, 2018 (last updated November 26, 2024)
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.
0
Attacker Value
Unknown
CVE-2018-7526
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access information in the application without authenticating.
0
Attacker Value
Unknown
CVE-2018-7518
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.
0
Attacker Value
Unknown
CVE-2018-11413
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by name=../application/database.php to read the MySQL credentials in the configuration.
0
Attacker Value
Unknown
CVE-2018-11414
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly.
0
Attacker Value
Unknown
CVE-2018-1259
Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2018-10299
Disclosure Date: April 23, 2018 (last updated November 26, 2024)
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.
0
Attacker Value
Unknown
CVE-2017-16670
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
0
Attacker Value
Unknown
CVE-2017-17595
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
0
Attacker Value
Unknown
CVE-2017-14486
Disclosure Date: December 01, 2017 (last updated November 26, 2024)
The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAIN SASL mechanism to send auth tokens to Vibease servers, which allows remote attackers to obtain user credentials, messages, and other sensitive information by sniffing the network for XMPP traffic.
0