|
198071
|
6.5 |
MEDIUM
Adjacent
|
tenda
|
f3_firmware
|
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-35391
|
2024-11-21 14:27 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198072
|
7.6 |
HIGH
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
|
CWE-89
SQL Injection
|
CVE-2020-35743
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198073
|
7.6 |
HIGH
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
|
CWE-89
SQL Injection
|
CVE-2020-35742
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198074
|
6.1 |
MEDIUM
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35741
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198075
|
6.1 |
MEDIUM
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35740
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198076
|
7.5 |
HIGH
Network
|
newgensoft
|
egov
|
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Objec…
|
NVD-CWE-Other
|
CVE-2020-35737
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198077
|
4.8 |
MEDIUM
Network
|
flatpress
|
flatpress
|
FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in Blog content via the admin panel. Each t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35241
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198078
|
4.8 |
MEDIUM
Network
|
fluxbb
|
fluxbb
|
FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in "Blog Content" and each time any user will …
|
CWE-79
Cross-site Scripting
|
CVE-2020-35240
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198079
|
4.7 |
MEDIUM
Network
|
vidyo
|
vidyo
|
Vidyo 02-09-/D allows clickjacking via the portal/ URI.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-35735
|
2024-11-21 14:27 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198080
|
6.1 |
MEDIUM
Network
|
roundcube fedoraproject debian
|
webmail fedora debian_linux
|
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference el…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35730
|
2024-11-21 14:27 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|