|
196771
|
6.1 |
MEDIUM
Network
|
appspace
|
on-prem
|
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5393
|
2024-11-21 14:34 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196772
|
4.8 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5843
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196773
|
8.8 |
HIGH
Network
|
ahsay
|
cloud_backup_suite
|
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-enc…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5846
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196774
|
6.8 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-5513
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196775
|
6.8 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-5512
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196776
|
7.2 |
HIGH
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-5515
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196777
|
9.1 |
CRITICAL
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5514
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196778
|
7.5 |
HIGH
Network
|
hashbrowncms
|
hashbrown_cms
|
An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.
|
CWE-22
Path Traversal
|
CVE-2020-5840
|
2024-11-21 14:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196779
|
9.8 |
CRITICAL
Network
|
litespeedtech
|
openlitespeed
|
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
|
CWE-20
Improper Input Validation
|
CVE-2020-5519
|
2024-11-21 14:34 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196780
|
9.8 |
CRITICAL
Network
|
apache
|
rust_sgx_sdk
|
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.
|
NVD-CWE-noinfo
|
CVE-2020-5499
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|