|
199341
|
6.1 |
MEDIUM
Network
|
cerberusftp
|
ftp_server
|
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5195
|
2024-11-21 14:33 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199342
|
6.1 |
MEDIUM
Network
|
phpgurukul
|
dairy_farm_shop_management_system
|
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5308
|
2024-11-21 14:33 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199343
|
5.4 |
MEDIUM
Network
|
powauth
|
pow
|
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a d…
|
CWE-384
Session Fixation
|
CVE-2020-5205
|
2024-11-21 14:33 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199344
|
7.5 |
HIGH
Network
|
ftpgetter
|
ftpgetter
|
FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string to the application. This memory corruption bug can possibly be classified as a …
|
CWE-787 CWE-476
Out-of-bounds Write NULL Pointer Dereference
|
CVE-2020-5183
|
2024-11-21 14:33 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199345
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
dairy_farm_shop_management_system
|
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, …
|
CWE-89
SQL Injection
|
CVE-2020-5307
|
2024-11-21 14:33 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199346
|
8.8 |
HIGH
Network
|
troglobit
|
uftpd
|
In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being filled via sprintf() with user input based on the for…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-5204
|
2024-11-21 14:33 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199347
|
8.8 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's dat…
|
CWE-89
SQL Injection
|
CVE-2020-5192
|
2024-11-21 14:33 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199348
|
6.1 |
MEDIUM
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5191
|
2024-11-21 14:33 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199349
|
4.8 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5306
|
2024-11-21 14:33 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199350
|
4.8 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5305
|
2024-11-21 14:33 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|