|
210221
|
9.8 |
CRITICAL
Network
|
13enforme
|
13enforme_cms
|
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-23979
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210222
|
9.8 |
CRITICAL
Network
|
soluzioneglobale
|
ecommerce_cms
|
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
|
CWE-89
SQL Injection
|
CVE-2020-23978
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210223
|
6.1 |
MEDIUM
Network
|
kandnconcepts_club_cms_project
|
kandnconcepts_club_cms
|
KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23977
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210224
|
9.8 |
CRITICAL
Network
|
webexcels
|
ecommerce_cms
|
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-23976
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210225
|
6.1 |
MEDIUM
Network
|
webexcels
|
ecommerce_cms
|
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23975
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210226
|
5.4 |
MEDIUM
Network
|
create-project_manager_project
|
create-project_manager
|
Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags).
|
CWE-79
Cross-site Scripting
|
CVE-2020-23974
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210227
|
9.8 |
CRITICAL
Network
|
kandnconcepts_club_cms_project
|
kandnconcepts_club_cms
|
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-23973
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210228
|
7.5 |
HIGH
Network
|
gmapfp
|
gmapfp
|
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricte…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23972
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210229
|
9.8 |
CRITICAL
Network
|
designmasterevents
|
conference_management
|
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
|
CWE-89
SQL Injection
|
CVE-2020-23980
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210230
|
5.3 |
MEDIUM
Network
|
ericom
|
access_server
|
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to infor…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24548
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|