|
209971
|
7.5 |
HIGH
Network
|
ntp redhat netapp debian opensuse
|
ntp enterprise_linux clustered_data_ontap virtual_storage_console data_ontap vasa_provider_for_clustered_data_ontap solidfire hci_management_node hci_storage_node_firmware …
|
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissi…
|
CWE-346
Origin Validation Error
|
CVE-2020-11868
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209972
|
7.5 |
HIGH
Network
|
appinghouse
|
memono
|
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-11826
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209973
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be va…
|
CWE-352
Origin Validation Error
|
CVE-2020-11825
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209974
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11823
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209975
|
9.8 |
CRITICAL
Network
|
rukovoditel
|
rukovoditel
|
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-11820
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209976
|
9.8 |
CRITICAL
Network
|
rukovoditel
|
rukovoditel
|
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.
|
CWE-22
Path Traversal
|
CVE-2020-11819
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209977
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid token. Thus, an attacker can change the Admin password…
|
CWE-352
Origin Validation Error
|
CVE-2020-11818
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209978
|
9.8 |
CRITICAL
Network
|
rukovoditel
|
rukovoditel
|
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) parameter.
|
CWE-89
SQL Injection
|
CVE-2020-11816
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209979
|
9.8 |
CRITICAL
Network
|
rukovoditel
|
rukovoditel
|
In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific at…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11815
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209980
|
5.4 |
MEDIUM
Network
|
qdpm
|
qdpm
|
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites.
|
CWE-74
Injection
|
CVE-2020-11814
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|