|
210041
|
5.3 |
MEDIUM
Network
|
oracle redhat
|
virtualization ovirt-engine
|
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the tar…
|
CWE-601
Open Redirect
|
CVE-2020-10775
|
2024-11-21 13:56 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
6.3 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-10780
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
8.3 |
HIGH
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to,…
|
NVD-CWE-noinfo
|
CVE-2020-10783
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
6.5 |
MEDIUM
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right cri…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-10779
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
6.0 |
MEDIUM
Network
|
redhat
|
cloudforms
|
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This busines…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-10778
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms
|
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using Clou…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10777
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
4.8 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10985
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
8.8 |
HIGH
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-10984
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
4.9 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.
|
CWE-89
SQL Injection
|
CVE-2020-10983
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
4.9 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.
|
CWE-89
SQL Injection
|
CVE-2020-10982
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|