|
199481
|
5.3 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the vi…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-35480
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199482
|
6.1 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is alway…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35479
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199483
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki …
|
CWE-79
Cross-site Scripting
|
CVE-2020-35478
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199484
|
5.3 |
MEDIUM
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggl…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2020-35477
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199485
|
7.5 |
HIGH
Network
|
mediawiki debian fedoraproject
|
mediawiki debian_linux fedora
|
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to ch…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35475
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199486
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35474
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199487
|
9.8 |
CRITICAL
Network
|
spotweb_project
|
spotweb
|
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
|
CWE-89
SQL Injection
|
CVE-2020-35545
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199488
|
8.1 |
HIGH
Network
|
fasterxml netapp debian oracle
|
jackson-databind service_level_manager debian_linux webcenter_portal application_testing_suite banking_platform agile_plm sd-wan_edge communications_services_gatekeeper ret…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35491
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199489
|
8.1 |
HIGH
Network
|
fasterxml netapp debian oracle
|
jackson-databind service_level_manager debian_linux webcenter_portal application_testing_suite banking_platform agile_plm communications_services_gatekeeper retail_merchandisi…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35490
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199490
|
10.0 |
CRITICAL
Network
|
rocklobster
|
contact_form_7
|
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35489
|
2024-11-21 14:27 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|