From 9882f3ab891d91e5674ff3c4471b503cf13da2d4 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Sun, 11 Nov 2018 12:04:55 -0500 Subject: [PATCH] - Synchronized data. --- 2018/19xxx/CVE-2018-19179.json | 18 ++++++++++ 2018/19xxx/CVE-2018-19180.json | 62 ++++++++++++++++++++++++++++++++++ 2018/19xxx/CVE-2018-19181.json | 62 ++++++++++++++++++++++++++++++++++ 2018/19xxx/CVE-2018-19182.json | 18 ++++++++++ 4 files changed, 160 insertions(+) create mode 100644 2018/19xxx/CVE-2018-19179.json create mode 100644 2018/19xxx/CVE-2018-19180.json create mode 100644 2018/19xxx/CVE-2018-19181.json create mode 100644 2018/19xxx/CVE-2018-19182.json diff --git a/2018/19xxx/CVE-2018-19179.json b/2018/19xxx/CVE-2018-19179.json new file mode 100644 index 00000000000..9a87a0556c4 --- /dev/null +++ b/2018/19xxx/CVE-2018-19179.json @@ -0,0 +1,18 @@ +{ + "CVE_data_meta" : { + "ASSIGNER" : "cve@mitre.org", + "ID" : "CVE-2018-19179", + "STATE" : "RESERVED" + }, + "data_format" : "MITRE", + "data_type" : "CVE", + "data_version" : "4.0", + "description" : { + "description_data" : [ + { + "lang" : "eng", + "value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} diff --git a/2018/19xxx/CVE-2018-19180.json b/2018/19xxx/CVE-2018-19180.json new file mode 100644 index 00000000000..472cf15f978 --- /dev/null +++ b/2018/19xxx/CVE-2018-19180.json @@ -0,0 +1,62 @@ +{ + "CVE_data_meta" : { + "ASSIGNER" : "cve@mitre.org", + "ID" : "CVE-2018-19180", + "STATE" : "PUBLIC" + }, + "affects" : { + "vendor" : { + "vendor_data" : [ + { + "product" : { + "product_data" : [ + { + "product_name" : "n/a", + "version" : { + "version_data" : [ + { + "version_value" : "n/a" + } + ] + } + } + ] + }, + "vendor_name" : "n/a" + } + ] + } + }, + "data_format" : "MITRE", + "data_type" : "CVE", + "data_version" : "4.0", + "description" : { + "description_data" : [ + { + "lang" : "eng", + "value" : "statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php." + } + ] + }, + "problemtype" : { + "problemtype_data" : [ + { + "description" : [ + { + "lang" : "eng", + "value" : "n/a" + } + ] + } + ] + }, + "references" : { + "reference_data" : [ + { + "name" : "https://github.com/doublefast/yunucms/issues/1", + "refsource" : "MISC", + "url" : "https://github.com/doublefast/yunucms/issues/1" + } + ] + } +} diff --git a/2018/19xxx/CVE-2018-19181.json b/2018/19xxx/CVE-2018-19181.json new file mode 100644 index 00000000000..69f7ad01ee1 --- /dev/null +++ b/2018/19xxx/CVE-2018-19181.json @@ -0,0 +1,62 @@ +{ + "CVE_data_meta" : { + "ASSIGNER" : "cve@mitre.org", + "ID" : "CVE-2018-19181", + "STATE" : "PUBLIC" + }, + "affects" : { + "vendor" : { + "vendor_data" : [ + { + "product" : { + "product_data" : [ + { + "product_name" : "n/a", + "version" : { + "version_data" : [ + { + "version_value" : "n/a" + } + ] + } + } + ] + }, + "vendor_name" : "n/a" + } + ] + } + }, + "data_format" : "MITRE", + "data_type" : "CVE", + "data_version" : "4.0", + "description" : { + "description_data" : [ + { + "lang" : "eng", + "value" : "statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file." + } + ] + }, + "problemtype" : { + "problemtype_data" : [ + { + "description" : [ + { + "lang" : "eng", + "value" : "n/a" + } + ] + } + ] + }, + "references" : { + "reference_data" : [ + { + "name" : "https://github.com/doublefast/yunucms/issues/1", + "refsource" : "MISC", + "url" : "https://github.com/doublefast/yunucms/issues/1" + } + ] + } +} diff --git a/2018/19xxx/CVE-2018-19182.json b/2018/19xxx/CVE-2018-19182.json new file mode 100644 index 00000000000..6ea6ba703ad --- /dev/null +++ b/2018/19xxx/CVE-2018-19182.json @@ -0,0 +1,18 @@ +{ + "CVE_data_meta" : { + "ASSIGNER" : "cve@mitre.org", + "ID" : "CVE-2018-19182", + "STATE" : "RESERVED" + }, + "data_format" : "MITRE", + "data_type" : "CVE", + "data_version" : "4.0", + "description" : { + "description_data" : [ + { + "lang" : "eng", + "value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +}