|
210411
|
5.3 |
MEDIUM
Network
|
motorola
|
cx2_firmware
|
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSetti…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21936
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210412
|
9.8 |
CRITICAL
Network
|
motorola
|
cx2_firmware
|
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2020-21935
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210413
|
7.5 |
HIGH
Network
|
motorola
|
cx2_firmware
|
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21934
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210414
|
7.5 |
HIGH
Network
|
motorola
|
cx2_firmware
|
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-21933
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210415
|
5.3 |
MEDIUM
Network
|
motorola
|
cx2_firmware
|
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
|
CWE-287
Improper Authentication
|
CVE-2020-21932
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210416
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
|
CWE-89
SQL Injection
|
CVE-2020-21133
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210417
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
|
CWE-89
SQL Injection
|
CVE-2020-21132
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210418
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
|
CWE-89
SQL Injection
|
CVE-2020-21131
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210419
|
5.4 |
MEDIUM
Network
|
publiccms
|
publiccms
|
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21333
|
2024-11-21 14:12 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210420
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20363
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|