|
209541
|
6.1 |
MEDIUM
Network
|
blog_mini_project
|
blog_mini
|
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18999
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209542
|
6.1 |
MEDIUM
Network
|
blog_mini_project
|
blog_mini
|
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18998
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209543
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
|
CWE-89
SQL Injection
|
CVE-2020-18477
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209544
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
|
CWE-89
SQL Injection
|
CVE-2020-18476
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209545
|
5.4 |
MEDIUM
Network
|
hucart
|
hucart
|
Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other user…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18475
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209546
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18470
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209547
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18469
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209548
|
5.4 |
MEDIUM
Network
|
qdpm
|
qdpm
|
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP req…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18468
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209549
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP …
|
CWE-79
Cross-site Scripting
|
CVE-2020-18467
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209550
|
5.4 |
MEDIUM
Network
|
popojicms
|
popojicms
|
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18065
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|