|
209461
|
7.5 |
HIGH
Network
|
motorola
|
cx2_firmware
|
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-21933
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209462
|
5.3 |
MEDIUM
Network
|
motorola
|
cx2_firmware
|
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
|
CWE-287
Improper Authentication
|
CVE-2020-21932
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209463
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
|
CWE-89
SQL Injection
|
CVE-2020-21133
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209464
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
|
CWE-89
SQL Injection
|
CVE-2020-21132
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209465
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
|
CWE-89
SQL Injection
|
CVE-2020-21131
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209466
|
5.4 |
MEDIUM
Network
|
publiccms
|
publiccms
|
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21333
|
2024-11-21 14:12 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209467
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20363
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209468
|
4.5 |
MEDIUM
Network
|
xyhcms
|
xyhcms
|
A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and pas…
|
CWE-352
Origin Validation Error
|
CVE-2020-20586
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209469
|
7.5 |
HIGH
Network
|
metinfo
|
metinfo
|
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-20585
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209470
|
6.1 |
MEDIUM
Network
|
baigo
|
baigo_cms
|
A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form parameter post to /public/console/profile/info-submit/.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20584
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|