|
210081
|
8.8 |
HIGH
Network
|
wwbn
|
avideo
|
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in plac…
|
CWE-862
Missing Authorization
|
CVE-2020-23489
|
2024-11-21 14:13 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210082
|
8.1 |
HIGH
Network
|
microweber
|
microweber
|
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session doe…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-23140
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210083
|
5.5 |
MEDIUM
Local
|
microweber
|
microweber
|
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a compl…
|
CWE-287
Improper Authentication
|
CVE-2020-23139
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210084
|
9.8 |
CRITICAL
Network
|
microweber
|
microweber
|
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23138
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210085
|
5.5 |
MEDIUM
Local
|
microweber
|
microweber
|
Microweber v1.1.18 is affected by no session expiry after log-out.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-23136
|
2024-11-21 14:13 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210086
|
9.8 |
CRITICAL
Network
|
jomsocial
|
jomsocial
|
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22274
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210087
|
6.5 |
MEDIUM
Network
|
creativeitem
|
neoflex_video_subscription_system
|
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
|
CWE-352
Origin Validation Error
|
CVE-2020-22273
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210088
|
8.8 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22278
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210089
|
8.0 |
HIGH
Network
|
codection
|
import_and_export_users_and_customers
|
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22277
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210090
|
9.8 |
CRITICAL
Network
|
weformspro
|
weforms
|
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22276
|
2024-11-21 14:13 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|