|
210951
|
7.0 |
HIGH
Local
|
timeshift_project fedoraproject canonical
|
timeshift fedora ubuntu_linux
|
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses…
|
CWE-362 CWE-59
Race Condition Link Following
|
CVE-2020-10174
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210952
|
8.8 |
HIGH
Network
|
comtrend
|
vr-3033_firmware
|
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metac…
|
CWE-78
OS Command
|
CVE-2020-10173
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210953
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
daily_expense_tracker_system
|
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10107
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210954
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
daily_expense_tracker_system
|
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database an…
|
CWE-89
SQL Injection
|
CVE-2020-10106
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210955
|
5.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an at…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-10105
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210956
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Ha…
|
CWE-200
Information Exposure
|
CVE-2020-10104
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210957
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10103
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210958
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors…
|
CWE-20 CWE-755
Improper Input Validation Improper Handling of Exceptional Conditions
|
CVE-2020-10101
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210959
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10099
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210960
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browse…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10098
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|