|
210621
|
6.1 |
MEDIUM
Network
|
shopex
|
ecshop
|
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20640
|
2024-11-21 14:12 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210622
|
9.8 |
CRITICAL
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21786
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210623
|
8.8 |
HIGH
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
|
CWE-77
Command Injection
|
CVE-2020-21785
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210624
|
9.8 |
CRITICAL
Network
|
phpwcms
|
phpwcms
|
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
|
CWE-94
Code Injection
|
CVE-2020-21784
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210625
|
6.1 |
MEDIUM
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21783
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210626
|
4.3 |
MEDIUM
Network
|
crmeb
|
crmeb
|
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21788
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210627
|
9.8 |
CRITICAL
Network
|
crmeb
|
crmeb
|
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21787
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210628
|
9.8 |
CRITICAL
Network
|
txjia
|
imcat
|
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
|
CWE-89
SQL Injection
|
CVE-2020-20392
|
2024-11-21 14:12 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210629
|
5.4 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20391
|
2024-11-21 14:12 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210630
|
4.8 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20389
|
2024-11-21 14:12 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|