|
211781
|
5.4 |
MEDIUM
Network
|
s-cms
|
s-cms
|
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19046
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211782
|
6.5 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
|
CWE-22
Path Traversal
|
CVE-2020-18127
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211783
|
5.4 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18126
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211784
|
6.1 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18125
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211785
|
5.7 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
|
CWE-352
Origin Validation Error
|
CVE-2020-18124
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211786
|
6.5 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-18123
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211787
|
8.8 |
HIGH
Network
|
indexhibit
|
indexhibit
|
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-18121
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211788
|
8.8 |
HIGH
Network
|
youdiancms
|
youdiancms
|
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-18116
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211789
|
9.8 |
CRITICAL
Network
|
dedecms
|
dedecms
|
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18114
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211790
|
9.8 |
CRITICAL
Network
|
wms_project
|
wms
|
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-18106
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|