|
211841
|
4.8 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-group.php by adding a question mark (…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10395
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211842
|
4.8 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-glossary.php by adding a question mar…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10394
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211843
|
4.8 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-field.php by adding a question mark (…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10393
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211844
|
4.8 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-category.php by adding a question mar…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10392
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211845
|
4.8 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-article.php by adding a question mark…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10391
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211846
|
7.2 |
HIGH
Network
|
chadhaajay
|
phpkb
|
OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by savin…
|
CWE-78
OS Command
|
CVE-2020-10390
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211847
|
7.2 |
HIGH
Network
|
chadhaajay
|
phpkb
|
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings.
|
CWE-94
Code Injection
|
CVE-2020-10389
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211848
|
5.4 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/report-…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10388
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211849
|
4.9 |
MEDIUM
Network
|
chadhaajay
|
phpkb
|
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter fil…
|
CWE-22
Path Traversal
|
CVE-2020-10387
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211850
|
7.2 |
HIGH
Network
|
chadhaajay
|
phpkb
|
admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10386
|
2024-11-21 13:55 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|