|
200711
|
9.8 |
CRITICAL
Network
|
point_of_sales_in_php\/pdo_project
|
point_of_sales_in_php\/pdo
|
SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.
|
CWE-89
SQL Injection
|
CVE-2020-29285
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200712
|
9.8 |
CRITICAL
Network
|
multi_restaurant_table_reservation_system_project
|
multi_restaurant_table_reservation_system
|
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can s…
|
CWE-89
SQL Injection
|
CVE-2020-29284
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200713
|
9.8 |
CRITICAL
Network
|
online_doctor_appointment_booking_system_php_and_mysql_project
|
online_doctor_appointment_booking_system_php_and_mysql
|
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
|
CWE-89
SQL Injection
|
CVE-2020-29283
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200714
|
9.8 |
CRITICAL
Network
|
bloodx_project
|
bloodx
|
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
|
CWE-89
SQL Injection
|
CVE-2020-29282
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200715
|
9.8 |
CRITICAL
Network
|
victor_cms_project
|
victor_cms
|
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
|
CWE-89
SQL Injection
|
CVE-2020-29280
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200716
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-29279
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200717
|
9.8 |
CRITICAL
Network
|
docker
|
crux_linux_docker_image
|
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29389
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200718
|
4.8 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview secti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29240
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200719
|
6.1 |
MEDIUM
Network
|
janobe
|
online_voting_system
|
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When …
|
CWE-79
Cross-site Scripting
|
CVE-2020-29239
|
2024-11-21 14:23 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200720
|
5.4 |
MEDIUM
Network
|
thinkadmin
|
thinkadmin
|
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29315
|
2024-11-21 14:23 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|