|
216811
|
7.5 |
HIGH
Network
|
midasolutions
|
eframework
|
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.
|
CWE-89
SQL Injection
|
CVE-2020-15924
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216812
|
7.5 |
HIGH
Network
|
midasolutions
|
eframework
|
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-15923
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216813
|
9.8 |
CRITICAL
Network
|
midasolutions
|
eframework
|
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
|
CWE-78
OS Command
|
CVE-2020-15922
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216814
|
9.8 |
CRITICAL
Network
|
midasolutions
|
eframework
|
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.
|
CWE-287
Improper Authentication
|
CVE-2020-15921
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216815
|
9.8 |
CRITICAL
Network
|
midasolutions
|
eframework
|
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
|
CWE-78
OS Command
|
CVE-2020-15920
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216816
|
6.1 |
MEDIUM
Network
|
midasolutions
|
eframework
|
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15919
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216817
|
5.4 |
MEDIUM
Network
|
midasolutions
|
eframework
|
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15918
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216818
|
9.8 |
CRITICAL
Network
|
claws-mail fedoraproject opensuse
|
claws-mail fedora leap backports_sle
|
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
|
NVD-CWE-noinfo
|
CVE-2020-15917
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216819
|
9.8 |
CRITICAL
Network
|
tenda
|
ac15_firmware
|
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
|
CWE-78
OS Command
|
CVE-2020-15916
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216820
|
6.5 |
MEDIUM
Adjacent
|
tesla
|
model_3_firmware
|
Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate this issue
|
NVD-CWE-noinfo
|
CVE-2020-15912
|
2024-11-21 14:06 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|