|
210751
|
7.5 |
HIGH
Network
|
meinbwa
|
direx-pro_firmware
|
BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-10248
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210752
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10247
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210753
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10246
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210754
|
7.5 |
HIGH
Network
|
jpaseto_project
|
jpaseto
|
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-10244
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210755
|
5.5 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive da…
|
CWE-362
Race Condition
|
CVE-2020-10237
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210756
|
6.1 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause…
|
CWE-20
Improper Input Validation
|
CVE-2020-10236
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210757
|
8.8 |
HIGH
Network
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed …
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2020-10235
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210758
|
9.1 |
CRITICAL
Network
|
sleuthkit
|
the_sleuth_kit
|
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10233
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210759
|
9.8 |
CRITICAL
Network
|
sleuthkit debian fedoraproject
|
the_sleuth_kit debian_linux fedora
|
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10232
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210760
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
job_portal
|
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to uploa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10225
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|