CVE-2018-19190
https://notcve.org/view.php?id=CVE-2018-19190
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter. El SDK de pasarela de pagos payfort-php-SDK de Amazon PAYFORT hasta el 26/04/2018 tiene Cross-Site Scripting (XSS) mediante el parámetro error_msg en error.php. • http://www.securityfocus.com/bid/105930 https://www.seekurity.com/blog/general/payfort-multiple-security-issues-and-concerns-in-a-supposed-to-be-pci-dss-compliant-payment-processor-sdk • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-19187
https://notcve.org/view.php?id=CVE-2018-19187
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement. El SDK de pasarela de pagos payfort-php-SDK de Amazon PAYFORT hasta el 26/04/2018 tiene Cross-Site Scripting (XSS) mediante un nombre de parámetro o valor arbitrario que se gestiona de manera incorrecta en una instrucción eco success.php. • http://www.securityfocus.com/bid/105930 https://www.seekurity.com/blog/general/payfort-multiple-security-issues-and-concerns-in-a-supposed-to-be-pci-dss-compliant-payment-processor-sdk • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-19186
https://notcve.org/view.php?id=CVE-2018-19186
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter. El SDK de pasarela de pagos payfort-php-SDK de Amazon PAYFORT hasta el 26/04/2018 tiene Cross-Site Scripting (XSS) mediante el parámetro paymentMethod en route.php. • https://www.seekurity.com/blog/general/payfort-multiple-security-issues-and-concerns-in-a-supposed-to-be-pci-dss-compliant-payment-processor-sdk • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-19188
https://notcve.org/view.php?id=CVE-2018-19188
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter. El SDK de pasarela de pagos payfort-php-SDK de Amazon PAYFORT hasta el 26/04/2018 tiene Cross-Site Scripting (XSS) mediante el parámetro fort_id en success.php. • http://www.securityfocus.com/bid/105930 https://github.com/payfort/payfort-php-sdk/issues/12 https://www.seekurity.com/blog/general/payfort-multiple-security-issues-and-concerns-in-a-supposed-to-be-pci-dss-compliant-payment-processor-sdk • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-11020
https://notcve.org/view.php?id=CVE-2018-11020
kernel/omap/drivers/rpmsg/rpmsg_omx.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device file /dev/rpmsg-omx1 with the command 3221772291, and cause a kernel crash. kernel/omap/drivers/rpmsg/rpmsg_omx.c en el componente kernel en Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 permite que los atacantes inyecten un argumento manipulado mediante el argumento de una llamada ioctl en el archivo del dispositivo /dev/rpmsg-omx1 con el comando 3221772291 y provoquen el cierre inesperado del kernel. • https://github.com/datadancer/HIAFuzz/blob/master/CVE-2018-11020.md https://github.com/datadancer/HIAFuzz/blob/master/CVE-Advisory.md • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •