|
210421
|
4.5 |
MEDIUM
Network
|
xyhcms
|
xyhcms
|
A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and pas…
|
CWE-352
Origin Validation Error
|
CVE-2020-20586
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210422
|
7.5 |
HIGH
Network
|
metinfo
|
metinfo
|
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-20585
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210423
|
6.1 |
MEDIUM
Network
|
baigo
|
baigo_cms
|
A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form parameter post to /public/console/profile/info-submit/.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20584
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210424
|
7.5 |
HIGH
Network
|
8cms
|
ljcms
|
A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-20583
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210425
|
7.5 |
HIGH
Network
|
mipcms
|
mipcms
|
A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-20582
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210426
|
8.8 |
HIGH
Network
|
crmeb
|
crmeb
|
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
|
CWE-89
SQL Injection
|
CVE-2020-21394
|
2024-11-21 14:12 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210427
|
6.1 |
MEDIUM
Network
|
ipfire
|
ipfire
|
Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21142
|
2024-11-21 14:12 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210428
|
6.1 |
MEDIUM
Network
|
shopex
|
ecshop
|
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20640
|
2024-11-21 14:12 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210429
|
9.8 |
CRITICAL
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21786
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210430
|
8.8 |
HIGH
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
|
CWE-77
Command Injection
|
CVE-2020-21785
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|