Show filters
733 Total Results
Displaying 331-340 of 733
Sort by:
Attacker Value
Unknown
CVE-2019-11010
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
0
Attacker Value
Unknown
CVE-2019-10107
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
0
Attacker Value
Unknown
CVE-2019-10106
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.
0
Attacker Value
Unknown
CVE-2019-10105
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.
0
Attacker Value
Unknown
CVE-2019-9059
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password" feature.
0
Attacker Value
Unknown
CVE-2019-9055
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.
0
Attacker Value
Unknown
CVE-2019-9058
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.
0
Attacker Value
Unknown
CVE-2019-9061
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.
0
Attacker Value
Unknown
CVE-2019-9057
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.
0
Attacker Value
Unknown
CVE-2019-10017
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
0