Show filters
144 Total Results
Displaying 51-60 of 144
Sort by:
Attacker Value
Unknown
CVE-2019-16065
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables and values, and potentially execute system-based commands as the mysql user. This affects the search_pattern value of the manage_hosts_short.cgi script.
0
Attacker Value
Unknown
CVE-2019-16066
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.
0
Attacker Value
Unknown
CVE-2019-16062
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.
0
Attacker Value
Unknown
CVE-2019-16064
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder. By exploiting this vulnerability, it is possible for an attacker to list operating-system directory contents on the server, create directories and upload files in permissible locations, and modify filenames and delete files that are accessible by the user running the web server instance.
0
Attacker Value
Unknown
CVE-2019-16070
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through web application form inputs.
0
Attacker Value
Unknown
CVE-2019-10799
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.
0
Attacker Value
Unknown
CVE-2020-9350
Disclosure Date: February 23, 2020 (last updated February 21, 2025)
Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.
0
Attacker Value
Unknown
CVE-2019-14678
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
0
Attacker Value
Unknown
CVE-2019-18798
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
0
Attacker Value
Unknown
CVE-2019-18797
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
0