|
210491
|
8.8 |
HIGH
Network
|
wdoyo
|
doyocms
|
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
|
CWE-89
SQL Injection
|
CVE-2020-19821
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210492
|
6.1 |
MEDIUM
Network
|
feehi
|
feehicms
|
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19709
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210493
|
9.8 |
CRITICAL
Network
|
thinkphp-zcms_project
|
thinkphp-zcms
|
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
|
CWE-89
SQL Injection
|
CVE-2020-19705
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210494
|
5.4 |
MEDIUM
Network
|
spring-boot-admin_project
|
spring-boot-admin
|
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19704
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210495
|
6.1 |
MEDIUM
Network
|
dzzoffice
|
dzzoffice
|
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19703
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210496
|
6.5 |
MEDIUM
Network
|
popojicms
|
popojicms
|
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
|
CWE-22
Path Traversal
|
CVE-2020-19547
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210497
|
8.8 |
HIGH
Network
|
eyoucms
|
eyoucms
|
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
|
CWE-352
Origin Validation Error
|
CVE-2020-19669
|
2024-11-21 14:09 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210498
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
|
CWE-22
Path Traversal
|
CVE-2020-19305
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210499
|
7.5 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
|
CWE-22
Path Traversal
|
CVE-2020-19304
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210500
|
7.8 |
HIGH
Local
|
houdunren
|
hdcms
|
An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19303
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|