|
211831
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can u…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26032
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211832
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26031
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211833
|
9.8 |
CRITICAL
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticate…
|
CWE-287
Improper Authentication
|
CVE-2020-26030
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211834
|
6.5 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not …
|
CWE-863
Incorrect Authorization
|
CVE-2020-26029
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211835
|
4.9 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
|
CWE-863
Incorrect Authorization
|
CVE-2020-26028
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211836
|
10.0 |
CRITICAL
Network
|
browserup
|
browserup_proxy
|
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it …
|
-
|
CVE-2020-26282
|
2024-11-21 14:19 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211837
|
8.5 |
HIGH
Network
|
gohugo
|
hugo
|
Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%…
|
CWE-78
OS Command
|
CVE-2020-26284
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211838
|
7.5 |
HIGH
Network
|
rust-lang
|
async-h1
|
async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async…
|
-
|
CVE-2020-26281
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211839
|
6.1 |
MEDIUM
Network
|
dbdeployer
|
dbdeployer
|
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files …
|
-
|
CVE-2020-26277
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211840
|
5.3 |
MEDIUM
Network
|
wireshark oracle
|
wireshark zfs_storage_appliance_kit
|
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-26422
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|