[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso
carnil at debian.org
Mon Nov 26 08:37:11 GMT 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a99b18a1 by Salvatore Bonaccorso at 2018-11-26T08:36:43Z
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,41 +1,41 @@
CVE-2018-19562 (An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip ...)
- TODO: check
+ NOT-FOR-US: PHPok
CVE-2018-19561 (sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an ...)
- TODO: check
+ NOT-FOR-US: sikcms
CVE-2018-19560 (BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate ...)
- TODO: check
+ NOT-FOR-US: BageCMS
CVE-2018-19559 (CuppaCMS before 2018-11-12 has SQL Injection in ...)
- TODO: check
+ NOT-FOR-US: CuppaCMS
CVE-2018-19558 (An issue was discovered in arcms through 2018-03-19. SQL injection ...)
TODO: check
CVE-2018-19557 (An issue was discovered in arcms through 2018-03-19. No authentication ...)
TODO: check
CVE-2018-19556 (zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles ...)
- TODO: check
+ NOT-FOR-US: Z-BlogPHP
CVE-2018-19555 (tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any ...)
- TODO: check
+ NOT-FOR-US: tp4a TELEPORT
CVE-2018-19554 (An issue was discovered in Dotcms through 5.0.3. Attackers may perform ...)
TODO: check
CVE-2018-19553 (Interspire Email Marketer through 6.1.6 has SQL Injection via an ...)
- TODO: check
+ NOT-FOR-US: Interspire Email Marketer
CVE-2018-19552 (Interspire Email Marketer through 6.1.6 has SQL Injection via a ...)
- TODO: check
+ NOT-FOR-US: Interspire Email Marketer
CVE-2018-19551 (Interspire Email Marketer through 6.1.6 has SQL Injection via a ...)
- TODO: check
+ NOT-FOR-US: Interspire Email Marketer
CVE-2018-19550 (Interspire Email Marketer through 6.1.6 allows arbitrary file upload ...)
- TODO: check
+ NOT-FOR-US: Interspire Email Marketer
CVE-2018-19549 (Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids ...)
- TODO: check
+ NOT-FOR-US: Interspire Email Marketer
CVE-2018-19548 (index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict ...)
TODO: check
CVE-2018-19547 (JTBC(PHP) 3.0.1.7 has XSS via the ...)
- TODO: check
+ NOT-FOR-US: JTBC(PHP)
CVE-2018-19546 (JTBC(PHP) 3.0.1.7 has CSRF via the ...)
- TODO: check
+ NOT-FOR-US: JTBC(PHP)
CVE-2018-19545 (JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. ...)
- TODO: check
+ NOT-FOR-US: JEECMS
CVE-2018-19544 (JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. ...)
- TODO: check
+ NOT-FOR-US: JEECMS
CVE-2018-19543 (An issue was discovered in JasPer 2.0.14. There is a heap-based buffer ...)
TODO: check
CVE-2018-19542 (An issue was discovered in JasPer 2.0.14. There is a NULL pointer ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a99b18a12a4225c313e1a6653f68ad295940eddd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a99b18a12a4225c313e1a6653f68ad295940eddd
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181126/c0817baa/attachment.html>
More information about the debian-security-tracker-commits
mailing list