|
212011
|
8.1 |
HIGH
Network
|
duxcms_project
|
duxcms
|
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
|
CWE-22
Path Traversal
|
CVE-2020-21862
|
2024-11-21 14:12 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212012
|
8.8 |
HIGH
Network
|
duxcms_project
|
duxcms
|
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21861
|
2024-11-21 14:12 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212013
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21489
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212014
|
6.1 |
MEDIUM
Network
|
alluxio
|
alluxio
|
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21485
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212015
|
9.8 |
CRITICAL
Network
|
nucleuscms
|
nucleuscms
|
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21474
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212016
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.
|
CWE-89
SQL Injection
|
CVE-2020-21400
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212017
|
8.0 |
HIGH
Network
|
njtech
|
greencms
|
Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-21366
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212018
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhicms
|
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21325
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212019
|
6.1 |
MEDIUM
Network
|
easycorp
|
zentao
|
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21268
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212020
|
8.8 |
HIGH
Network
|
hongcms_project
|
hongcms
|
Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-21252
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|