CVE-2018-10933.zip
1010 B
CVE-2018-10933
Author: opsifiz

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

GitHub Link:
https://github.com/opsifiz/CVE-2018-10933
CVE-2018-17254.zip
2.5 KB
CVE-2018-17254
Author: 7amzahard

The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.

GitHub Link:
https://github.com/7amzahard/script-python-to-detect-CVE-2018-17254
CVE-2021-23394
Author: 0xnemian

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

GitHub Link:
https://github.com/0xnemian/CVE-2021-23394