Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-17246 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
network
low complexity
elastic redhat CWE-829
critical
9.8
2018-11-28 CVE-2018-12120 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Nodejs Node.Js
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default.
network
high complexity
nodejs CWE-829
8.1
2018-10-29 CVE-2018-18387 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Playsms Project Playsms
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
network
low complexity
playsms-project CWE-829
8.8
2018-09-07 CVE-2018-15486 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Kone Group Controller Firmware
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5.
network
low complexity
kone CWE-829
critical
9.1
2018-08-15 CVE-2018-8351 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Microsoft Edge and Internet Explorer
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
network
low complexity
microsoft CWE-829
6.5
2018-06-26 CVE-2018-1000502 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mybb
MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance -> Task Manager -> Add New Task) that can result in Allows Local File Inclusion on modern PHP versions and Remote File Inclusion on ancient PHP versions.
network
low complexity
mybb CWE-829
7.2
2018-06-25 CVE-2018-11040 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests.
network
low complexity
vmware oracle debian CWE-829
7.5
2018-06-11 CVE-2017-5397 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mozilla Firefox
The cache directory on the local file system is set to be world writable.
network
low complexity
mozilla CWE-829
critical
9.8
2018-03-19 CVE-2018-7422 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Siteeditor Site Editor 1.0.0/1.1.0/1.1.1
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.
network
low complexity
siteeditor CWE-829
7.5
2018-01-19 CVE-2017-14095 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Trendmicro Smart Protection Server
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.
network
high complexity
trendmicro CWE-829
8.1