|
199751
|
9.8 |
CRITICAL
Network
|
car_rental_management_system_project
|
car_rental_management_system
|
An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, t…
|
NVD-CWE-noinfo
|
CVE-2020-29227
|
2024-11-21 14:23 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199752
|
8.8 |
HIGH
Network
|
tiki
|
tikiwiki_cms\/groupware
|
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary a…
|
CWE-352
Origin Validation Error
|
CVE-2020-29254
|
2024-11-21 14:23 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199753
|
3.5 |
LOW
Network
|
opencart
|
opencart
|
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.
|
CWE-352
Origin Validation Error
|
CVE-2020-28838
|
2024-11-21 14:23 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199754
|
9.8 |
CRITICAL
Network
|
ubilling
|
ubilling
|
Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.
|
CWE-78 CWE-306
OS Command Missing Authentication for Critical Function
|
CVE-2020-29311
|
2024-11-21 14:23 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199755
|
5.4 |
MEDIUM
Network
|
online_examination_system_project
|
online_examination_system
|
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29259
|
2024-11-21 14:23 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199756
|
6.1 |
MEDIUM
Network
|
online_examination_system_project
|
online_examination_system
|
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29258
|
2024-11-21 14:23 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199757
|
6.1 |
MEDIUM
Network
|
online_examination_system_project
|
online_examination_system
|
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29257
|
2024-11-21 14:23 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199758
|
7.5 |
HIGH
Network
|
plummac
|
ik-401_firmware
|
An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain the configuration file, including hashed credenti…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-28946
|
2024-11-21 14:23 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199759
|
5.5 |
MEDIUM
Local
|
nlnetlabs debian
|
unbound name_server_daemon debian_linux
|
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing …
|
CWE-59
Link Following
|
CVE-2020-28935
|
2024-11-21 14:23 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199760
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28727
|
2024-11-21 14:23 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|