|
199451
|
5.3 |
MEDIUM
Network
|
titanhq
|
spamtitan
|
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
|
CWE-552 CWE-312
Files or Directories Accessible to External Parties Cleartext Storage of Sensitive Information
|
CVE-2020-35658
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199452
|
7.2 |
HIGH
Network
|
jaws_project
|
jaws
|
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35657
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199453
|
7.2 |
HIGH
Network
|
jaws_project
|
jaws
|
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGad…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35656
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199454
|
5.5 |
MEDIUM
Local
|
microsoft
|
azure_sphere
|
A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacke…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-35609
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199455
|
7.8 |
HIGH
Local
|
microsoft
|
azure_sphere
|
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an …
|
CWE-74
Injection
|
CVE-2020-35608
|
2024-11-21 14:27 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199456
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks agains…
|
CWE-352
Origin Validation Error
|
CVE-2020-35626
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199457
|
8.8 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (de…
|
CWE-862
Missing Authorization
|
CVE-2020-35625
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199458
|
5.3 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-35624
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199459
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters with…
|
CWE-20 CWE-706
Improper Input Validation Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-35623
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199460
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function wa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35622
|
2024-11-21 14:27 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|