CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has not agreed that this issue has serious impact. The vendor states that the issue is not critical because it does not allow Elevation of Privilege, Sensitive Data Leakage, or any critical unauthorized activity from a malicious user. The vendor also states that a victim must first install a malicious APK to their application.
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
A vulnerability in the chat feed feature of Cisco SocialMiner could allow an unauthenticated, remote attacker to perform cross-site scripting (XSS) attacks against a user of the web-based user interface of an affected system. This vulnerability is due to insufficient sanitization of user-supplied input delivered to the chat feed as part of an HTTP request. An attacker could exploit this vulnerability by persuading a user to follow a link to attacker-controlled content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
Ie-sw-pl09m-5gc-4gt_firmware, Ie-sw-pl09m-5gc-4gt, Ie-sw-pl09mt-5gc-4gt_firmware, Ie-sw-pl09mt-5gc-4gt, Ie-sw-pl18m-2gc-16tx_firmware, Ie-sw-pl18m-2gc-16tx, Ie-sw-pl18mt-2gc-16tx_firmware, Ie-sw-pl18mt-2gc-16tx, Ie-sw-pl18m-2gc14tx2sc_firmware, Ie-sw-pl18m-2gc14tx2sc
2021-07-21
N/A
9.8 CRITICAL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin password compromise when captured on the network.
Ie-sw-pl09m-5gc-4gt_firmware, Ie-sw-pl09m-5gc-4gt, Ie-sw-pl09mt-5gc-4gt_firmware, Ie-sw-pl09mt-5gc-4gt, Ie-sw-pl18m-2gc-16tx_firmware, Ie-sw-pl18m-2gc-16tx, Ie-sw-pl18mt-2gc-16tx_firmware, Ie-sw-pl18mt-2gc-16tx, Ie-sw-pl18m-2gc14tx2sc_firmware, Ie-sw-pl18m-2gc14tx2sc
2019-12-10
N/A
6.5 MEDIUM
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device.
