|
209961
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25120
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209962
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25119
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209963
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25118
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209964
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25117
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209965
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25116
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209966
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25115
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209967
|
6.1 |
MEDIUM
Network
|
advanced_reports_project
|
advanced_reports
|
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaSc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25102
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209968
|
9.8 |
CRITICAL
Network
|
eramba
|
eramba
|
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-25105
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209969
|
5.4 |
MEDIUM
Network
|
eramba
|
eramba
|
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25104
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209970
|
7.5 |
HIGH
Network
|
setelsa-security
|
conacwin
|
Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/.…
|
CWE-22
Path Traversal
|
CVE-2020-25068
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|