|
210671
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25091
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210672
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25090
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210673
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25089
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210674
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25088
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210675
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25087
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210676
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25086
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210677
|
8.8 |
HIGH
Network
|
dlink
|
dcs-2530l_firmware dcs-2670l_firmware
|
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
|
CWE-77
Command Injection
|
CVE-2020-25079
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210678
|
7.5 |
HIGH
Network
|
dlink
|
dcs-2530l_firmware dcs-2670l_firmware
|
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
|
NVD-CWE-noinfo
|
CVE-2020-25078
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210679
|
5.3 |
MEDIUM
Network
|
debian
|
freedombox
|
FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageK…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25073
|
2024-11-21 14:17 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210680
|
8.8 |
HIGH
Network
|
usvn
|
usvn
|
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
|
CWE-352
Origin Validation Error
|
CVE-2020-25070
|
2024-11-21 14:17 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|