Total
7706 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-17826 | 1 Hisiphp | 1 Hisiphp | 2024-11-21 | N/A |
HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico). | ||||
CVE-2018-17792 | 1 Altn | 1 Mdaemon Webmail | 2024-11-21 | N/A |
MDaemon Webmail (formerly WorldClient) has CSRF. | ||||
CVE-2018-17789 | 1 Prospecta | 1 Master Data Online | 2024-11-21 | 6.5 Medium |
Prospecta Master Data Online (MDO) allows CSRF. | ||||
CVE-2018-17584 | 1 Wpfastestcache | 1 Wp Fastest Cache | 2024-11-21 | N/A |
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page. | ||||
CVE-2018-17429 | 1 Jtbc | 1 Jtbc | 2024-11-21 | N/A |
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account. | ||||
CVE-2018-17389 | 1 Ranksol | 1 Live Call Support | 2024-11-21 | N/A |
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. | ||||
CVE-2018-17387 | 1 Ranksol | 1 Nimble Professional | 2024-11-21 | N/A |
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. | ||||
CVE-2018-17366 | 1 Mcms Project | 1 Mcms | 2024-11-21 | N/A |
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | ||||
CVE-2018-17168 | 1 Printeron | 1 Printeron | 2024-11-21 | N/A |
PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can be tricked into making unwanted changes to a printer (Disable, Approve, etc). | ||||
CVE-2018-17104 | 1 Microweber | 1 Microweber | 2024-11-21 | N/A |
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user. | ||||
CVE-2018-17103 | 1 Get-simple | 1 Getsimple Cms | 2024-11-21 | N/A |
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter | ||||
CVE-2018-17102 | 1 Quickappscms | 1 Quickapps Cms | 2024-11-21 | N/A |
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI. | ||||
CVE-2018-17081 | 1 E107 | 1 E107 | 2024-11-21 | N/A |
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page. | ||||
CVE-2018-17070 | 1 Unlcms | 1 Unlcms | 2024-11-21 | N/A |
An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay. | ||||
CVE-2018-17069 | 1 Unlcms | 1 Unlcms | 2024-11-21 | N/A |
An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay. | ||||
CVE-2018-17045 | 1 Cms Maelostore Project | 1 Cms Maelostore | 2024-11-21 | N/A |
An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aksi_users.php?act=update. | ||||
CVE-2018-17023 | 1 Asus | 2 Gt-ac5300, Gt-ac5300 Firmware | 2024-11-21 | N/A |
Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to start_apply.htm. | ||||
CVE-2018-16966 | 1 Filemanagerpro | 1 File Manager | 2024-11-21 | N/A |
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | ||||
CVE-2018-16952 | 1 Oracle | 1 Webcenter Interaction | 2024-11-21 | N/A |
The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its design. The impact is sensitive actions in the portal (such as changing a portal user's password). NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support. | ||||
CVE-2018-16951 | 1 Xunfeng Project | 1 Xunfeng | 2024-11-21 | N/A |
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832. |