|
210941
|
9.8 |
CRITICAL
Network
|
motorola
|
cx2_firmware
|
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2020-21935
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210942
|
7.5 |
HIGH
Network
|
motorola
|
cx2_firmware
|
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21934
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210943
|
7.5 |
HIGH
Network
|
motorola
|
cx2_firmware
|
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-21933
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210944
|
5.3 |
MEDIUM
Network
|
motorola
|
cx2_firmware
|
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
|
CWE-287
Improper Authentication
|
CVE-2020-21932
|
2024-11-21 14:12 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210945
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
|
CWE-89
SQL Injection
|
CVE-2020-21133
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210946
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
|
CWE-89
SQL Injection
|
CVE-2020-21132
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210947
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
|
CWE-89
SQL Injection
|
CVE-2020-21131
|
2024-11-21 14:12 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210948
|
5.4 |
MEDIUM
Network
|
publiccms
|
publiccms
|
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21333
|
2024-11-21 14:12 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210949
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20363
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210950
|
4.5 |
MEDIUM
Network
|
xyhcms
|
xyhcms
|
A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and pas…
|
CWE-352
Origin Validation Error
|
CVE-2020-20586
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|