WAFPlanet

CVE Database - 2018

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

6718
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2018-0723

MEDIUM
6.10 CVSS 3.0

Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-17957

HIGH
7.80 CVSS 3.0

The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.

Improper Authentication
WAF: Low

CVE-2018-20480

CRITICAL
9.80 CVSS 3.0

An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.

SQL Injection
WAF: High

CVE-2018-20479

CRITICAL
9.80 CVSS 3.0

An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.

SQL Injection
WAF: High

CVE-2018-20477

CRITICAL
9.80 CVSS 3.0

An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.

SQL Injection
WAF: High

CVE-2018-20476

MEDIUM
6.10 CVSS 3.0

An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20464

MEDIUM
6.10 CVSS 3.0

There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20463

HIGH
7.50 CVSS 3.0

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

Path Traversal
WAF: High

CVE-2018-20462

MEDIUM
6.10 CVSS 3.0

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20454

MEDIUM
6.10 CVSS 3.0

An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20448

MEDIUM
5.40 CVSS 3.0

Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20437

HIGH
7.50 CVSS 3.0

An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data

Path Traversal
WAF: High

CVE-2018-20436

HIGH
8.10 CVSS 3.0

The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also affects one or more other Telegram products, such as Telegram Web-version 0.7.0. In addition, it can be interpreted as an SSRF issue. NOTE: a third party has reported that potentially unwanted behavior is caused by misconfiguration of the "Secret chats > Preview links" setting

Server-Side Request Forgery (SSRF)
WAF: Medium

CVE-2018-18960

MEDIUM
5.90 CVSS 3.0

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to find certain devices on the network, but the default version is v2c, allowing an amplification attack.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2018-7837

HIGH
7.50 CVSS 3.0

An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect documents into its output and expose restricted information.

XML External Entity (XXE)
WAF: High

CVE-2018-7836

CRITICAL
9.80 CVSS 3.0

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

Unrestricted File Upload
WAF: Medium

CVE-2018-7835

HIGH
7.50 CVSS 3.0

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow access to files available to SYSTEM user.

Path Traversal
WAF: High

CVE-2018-7832

HIGH
8.80 CVSS 3.0

An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched.

Improper Input Validation
WAF: Medium

CVE-2018-7802

HIGH
8.80 CVSS 3.0

A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.

SQL Injection
WAF: High

CVE-2018-7801

HIGH
8.80 CVSS 3.1

A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote code execution is performed.

Code Injection
WAF: Medium

CVE-2018-8917

MEDIUM
5.40 CVSS 3.0

Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-8918

MEDIUM
5.40 CVSS 3.0

Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-15465

HIGH
8.10 CVSS 3.0

A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.

Incorrect Authorization
WAF: Low

CVE-2018-20433

CRITICAL
9.80 CVSS 3.0

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

XML External Entity (XXE)
WAF: High

CVE-2018-20424

MEDIUM
5.90 CVSS 3.0

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

Improper Input Validation
WAF: Medium

CVE-2018-20422

HIGH
8.10 CVSS 3.0

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).

Improper Authentication
WAF: Low

CVE-2018-20418

MEDIUM
4.80 CVSS 3.0

index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20419

HIGH
8.80 CVSS 3.0

DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2018-20379

MEDIUM
4.70 CVSS 3.0

Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20373

MEDIUM
5.40 CVSS 3.0

Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20372

MEDIUM
5.40 CVSS 3.0

TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20370

MEDIUM
5.40 CVSS 3.0

SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20369

MEDIUM
6.10 CVSS 3.0

Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20368

MEDIUM
5.40 CVSS 3.0

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20367

MEDIUM
6.10 CVSS 3.0

The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent parameter, as demonstrated by the index.php/home/goodsconsult/add.html URI.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20351

MEDIUM
6.10 CVSS 3.0

The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20325

CRITICAL
9.80 CVSS 3.0

There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.

Code Injection
WAF: Medium

CVE-2018-20322

MEDIUM
6.10 CVSS 3.0

LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20193

HIGH
8.80 CVSS 3.0

Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1R5 (build 9627) 4.2 Release (build 7631). This occurs because appropriate controls are not performed. Specifically, it is possible for a readonly user to change the administrator user password by making a local copy of the /dana-admin/user/update.cgi page, changing the "user" value, and saving the changes.

Improper Privilege Management
WAF: Low

CVE-2018-16778

MEDIUM
6.10 CVSS 3.0

Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field).

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20342

MEDIUM
6.80 CVSS 3.0

The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.

Improper Authentication
WAF: Low

CVE-2018-20339

MEDIUM
6.10 CVSS 3.0

Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20338

CRITICAL
9.80 CVSS 3.0

Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.

SQL Injection
WAF: High

CVE-2018-20332

HIGH
7.50 CVSS 3.0

An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and listing of arbitrary directories is possible with /file?action=download&dir= followed by a full pathname. This is related to plugin/controllers/file.py in the e2openplugin-OpenWebif project.

Path Traversal
WAF: High

CVE-2018-20329

HIGH
8.10 CVSS 3.0

Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.

SQL Injection
WAF: High

CVE-2018-20328

MEDIUM
5.40 CVSS 3.0

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20327

MEDIUM
5.40 CVSS 3.0

Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

Cross-Site Scripting (XSS)
WAF: High

CVE-2018-20318

CRITICAL
9.80 CVSS 3.0

An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.

XML External Entity (XXE)
WAF: High

CVE-2018-19239

HIGH
7.20 CVSS 3.0

TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.

OS Command Injection
WAF: High

CVE-2018-18399

CRITICAL
9.80 CVSS 3.0

SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.

SQL Injection
WAF: High
Page 3 of 135 (6718 CVEs)