Skip to content

Commit 0f00238

Browse files
Sync EUVD catalog: Sun May 31 00:56:39 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 0bb817c commit 0f00238

353 files changed

Lines changed: 6113 additions & 1033 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21927",
3+
"enisaUuid": "4c9ed5d4-78a7-37d6-bc00-9583a17ba6e4",
4+
"description": "eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters to extract sensitive database information including usernames, database names, and version details.",
5+
"datePublished": "May 30, 2026, 2:55:12 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:12 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45654\nhttp://www.endonesia.org/\nhttps://sourceforge.net/projects/endonesia/files/latest/download\nhttps://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php\n",
11+
"aliases": "GHSA-7976-cwgg-p8cx\nCVE-2018-25405\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "8a499a27-8d9f-36ba-9747-0f9668c9ca87",
17+
"product": {
18+
"name": "eNdonesia Portal",
19+
"vendor": {
20+
"name": "Endonesia"
21+
}
22+
},
23+
"product_version": "8.7"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7af63706-65a4-3653-98cc-400999c673c5",
29+
"vendor": {
30+
"name": "Endonesia"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21928",
3+
"enisaUuid": "82f71f94-29ef-347e-a5c7-d6b9cf68f881",
4+
"description": "eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database credentials, usernames, and version information.",
5+
"datePublished": "May 30, 2026, 2:55:14 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:14 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45654\nhttp://www.endonesia.org/\nhttps://sourceforge.net/projects/endonesia/files/latest/download\nhttps://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php-2\n",
11+
"aliases": "GHSA-pj9c-49f9-pw37\nCVE-2018-25406\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "c88f0314-a648-3770-b701-eb5c1b654bea",
17+
"product": {
18+
"name": "eNdonesia Portal",
19+
"vendor": {
20+
"name": "Endonesia"
21+
}
22+
},
23+
"product_version": "8.7"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "6ce27ecb-6f33-3ac6-91ff-134f8615c785",
29+
"vendor": {
30+
"name": "Endonesia"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21929",
3+
"enisaUuid": "0b8fbbfd-7204-3410-9489-3cea81f2679d",
4+
"description": "eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database information including usernames, database names, and version details.",
5+
"datePublished": "May 30, 2026, 2:55:14 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:14 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45654\nhttp://www.endonesia.org/\nhttps://sourceforge.net/projects/endonesia/files/latest/download\nhttps://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php-3\n",
11+
"aliases": "CVE-2018-25407\nGHSA-34x7-vqxj-ppp4\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "5846a951-9e4d-39ed-85ea-8eb486025bd9",
17+
"product": {
18+
"name": "eNdonesia Portal",
19+
"vendor": {
20+
"name": "Endonesia"
21+
}
22+
},
23+
"product_version": "8.7"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "4183b3d9-3d33-3cd6-b9ca-c59fa36dfa24",
29+
"vendor": {
30+
"name": "Endonesia"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21930",
3+
"enisaUuid": "e5d22890-9047-3422-8996-9c7a0834477c",
4+
"description": "The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.",
5+
"datePublished": "May 30, 2026, 2:55:15 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:15 PM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45655\nhttp://openises.sourceforge.net/\nhttps://sourceforge.net/projects/openises/files/latest/download\nhttps://www.vulncheck.com/advisories/the-open-ises-project-3-30a-path-traversal-arbitrary-file-download\n",
11+
"aliases": "CVE-2018-25408\nGHSA-39jc-xvx2-95jh\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "43af081c-212f-31a0-980d-cc0bf81185c9",
17+
"product": {
18+
"name": "Open ISES Project",
19+
"vendor": {
20+
"name": "Open ISES"
21+
}
22+
},
23+
"product_version": "3.30A"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "9d913323-e240-321f-b46c-e4a20f0f58e6",
29+
"vendor": {
30+
"name": "openises"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21931",
3+
"enisaUuid": "5378d5ae-cb71-31d6-a9cb-891bd8aa03e3",
4+
"description": "SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts.",
5+
"datePublished": "May 30, 2026, 2:55:16 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:16 PM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45659\nhttps://simpkh.sourceforge.io/\nhttps://sourceforge.net/projects/simpkh/files/latest/download\nhttps://www.vulncheck.com/advisories/sim-pkh-arbitrary-file-upload-via-aksi-pengurus-php\n",
11+
"aliases": "CVE-2018-25409\nGHSA-j699-2v84-mrr9\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7d5be35e-164d-3b8a-9d08-1181b0ef5dfe",
17+
"product": {
18+
"name": "SIM-PKH",
19+
"vendor": {
20+
"name": "Simpkh"
21+
}
22+
},
23+
"product_version": "2.4.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "170897de-a061-3d6c-a5ce-9fa651a8cccf",
29+
"vendor": {
30+
"name": "Simpkh"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21932",
3+
"enisaUuid": "beb745c5-9198-3185-997a-0526ba47ef26",
4+
"description": "SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to /admin/media.php with module=pengurus and act=editpengurus parameters containing SQL UNION statements to extract database information including usernames, database names, and version details.",
5+
"datePublished": "May 30, 2026, 2:55:17 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:17 PM",
7+
"baseScore": 7.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45664\nhttps://simpkh.sourceforge.io/\nhttps://sourceforge.net/projects/simpkh/files/latest/download\nhttps://www.vulncheck.com/advisories/sim-pkh-sql-injection-via-media-php-id-parameter\n",
11+
"aliases": "CVE-2018-25410\nGHSA-f67q-74gf-3w9f\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "8d568417-8272-3350-8995-7714f77dc916",
17+
"product": {
18+
"name": "SIM-PKH",
19+
"vendor": {
20+
"name": "Simpkh"
21+
}
22+
},
23+
"product_version": "2.4.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "1575132a-060a-3259-94a6-6ef642a86ca3",
29+
"vendor": {
30+
"name": "Simpkh"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21933",
3+
"enisaUuid": "1f8f63ee-745e-3c3f-a838-1da29d5bbd61",
4+
"description": "MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table and column names.",
5+
"datePublished": "May 30, 2026, 2:55:17 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:17 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45665\nhttp://www.m-gb.org/\nhttps://sourceforge.net/projects/mopzz-gb/files/latest/download\nhttps://www.vulncheck.com/advisories/mgb-opensource-guestbook-sql-injection-via-email-php\n",
11+
"aliases": "CVE-2018-25411\nGHSA-p2q6-28xf-prjj\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "a85dae08-d160-3e84-984d-e5a84fa19b2c",
17+
"product": {
18+
"name": "MGB OpenSource Guestbook",
19+
"vendor": {
20+
"name": "M-Gb"
21+
}
22+
},
23+
"product_version": "0.7.0.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "96ffc716-afad-311b-804a-0666da610f64",
29+
"vendor": {
30+
"name": "M-Gb"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21934",
3+
"enisaUuid": "95a91501-a633-3758-a5ca-f44e982cff83",
4+
"description": "Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.",
5+
"datePublished": "May 30, 2026, 2:55:18 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:18 PM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45685\nhttp://deltasql.sourceforge.net/\nhttps://sourceforge.net/projects/deltasql/files/latest/download\nhttp://deltasql.sourceforge.net/deltasql/\nhttps://www.vulncheck.com/advisories/delta-sql-arbitrary-file-upload-via-docs-upload-php\n",
11+
"aliases": "GHSA-q3h9-349m-77jh\nCVE-2018-25412\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "25cce844-f357-342f-a7ff-8620aefa98df",
17+
"product": {
18+
"name": "Delta Sql",
19+
"vendor": {
20+
"name": "Deltasql"
21+
}
22+
},
23+
"product_version": "1.8.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "92808e22-51c6-345f-901c-1949dce86c67",
29+
"vendor": {
30+
"name": "Deltasql"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21935",
3+
"enisaUuid": "8a5618d6-b99e-3b01-bfe6-5eeb880bb729",
4+
"description": "AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.",
5+
"datePublished": "May 30, 2026, 2:55:19 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:19 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45690\nhttps://aiopmsd.sourceforge.io/\nhttps://sourceforge.net/projects/aiopmsd/files/latest/download\nhttps://www.vulncheck.com/advisories/aiopmsd-final-sql-injection-via-search-php\n",
11+
"aliases": "CVE-2018-25413\nGHSA-r4jm-2v38-pg5c\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "06bd9b47-b924-3364-94ba-9bfff150fdf7",
17+
"product": {
18+
"name": "AiOPMSD Final",
19+
"vendor": {
20+
"name": "Aiopmsd"
21+
}
22+
},
23+
"product_version": "1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "f536d5cd-62f6-3fb2-86fa-fbaf929003e1",
29+
"vendor": {
30+
"name": "Aiopmsd"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2018-21936",
3+
"enisaUuid": "6100d703-4b23-39f8-b298-3ff09cfc8a42",
4+
"description": "AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor parameter to extract sensitive database information including usernames, database names, and version details.",
5+
"datePublished": "May 30, 2026, 2:55:20 PM",
6+
"dateUpdated": "May 30, 2026, 2:55:20 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45690\nhttps://aiopmsd.sourceforge.io/\nhttps://sourceforge.net/projects/aiopmsd/files/latest/download\nhttps://www.vulncheck.com/advisories/aiopmsd-final-sql-injection-via-actor-php\n",
11+
"aliases": "CVE-2018-25414\nGHSA-xmj7-wr6h-chm4\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "dad4e609-2b7c-35dd-a9f8-85c6a06a78dd",
17+
"product": {
18+
"name": "AiOPMSD Final",
19+
"vendor": {
20+
"name": "Aiopmsd"
21+
}
22+
},
23+
"product_version": "1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "6e7b149f-afe3-326d-91e2-1473c8e78231",
29+
"vendor": {
30+
"name": "Aiopmsd"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)