|
197581
|
7.5 |
HIGH
Network
|
proftpd siemens opensuse
|
proftpd simatic_net_cp_1543-1_firmware simatic_net_cp_1545-1_firmware leap backports_sle
|
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9272
|
2024-11-21 14:40 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197582
|
8.8 |
HIGH
Network
|
libarchive canonical fedoraproject
|
libarchive ubuntu_linux fedora
|
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unsp…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9308
|
2024-11-21 14:40 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197583
|
6.5 |
MEDIUM
Network
|
icehrm
|
icehrm
|
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9271
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197584
|
8.8 |
HIGH
Network
|
icehrm
|
icehrm
|
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9270
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197585
|
7.2 |
HIGH
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.
|
CWE-89
SQL Injection
|
CVE-2020-9269
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197586
|
7.5 |
HIGH
Network
|
soplanning
|
soplanning
|
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
|
CWE-89
SQL Injection
|
CVE-2020-9268
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197587
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9267
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197588
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9266
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197589
|
8.2 |
HIGH
Network
|
ciprianmp
|
phpmychat-plus
|
phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.
|
CWE-89
SQL Injection
|
CVE-2020-9265
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197590
|
5.5 |
MEDIUM
Local
|
eset
|
nod32_antivirus internet_security smart_security mobile_security smart_tv_security cyber_security
|
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Intern…
|
CWE-436
Interpretation Conflict
|
CVE-2020-9264
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|