|
210621
|
8.1 |
HIGH
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
|
CWE-352
Origin Validation Error
|
CVE-2020-19886
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210622
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19885
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210623
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19884
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210624
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19883
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210625
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php lin…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19882
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210626
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can e…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19881
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210627
|
6.1 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthenticated attacker can exploit this vulnerability to hijack other…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19880
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210628
|
6.1 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,
|
CWE-79
Cross-site Scripting
|
CVE-2020-19879
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210629
|
7.5 |
HIGH
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php, A remote unauthenticated attacker can exploit this vulnerabil…
|
NVD-CWE-noinfo
|
CVE-2020-19878
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210630
|
5.3 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain serve…
|
CWE-22
Path Traversal
|
CVE-2020-19877
|
2024-11-21 14:09 |
2020-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|