|
209441
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST …
|
CWE-79
Cross-site Scripting
|
CVE-2020-19049
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209442
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP r…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19048
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209443
|
8.8 |
HIGH
Network
|
iwebshop
|
iwebshop
|
Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.
|
CWE-352
Origin Validation Error
|
CVE-2020-19047
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209444
|
5.4 |
MEDIUM
Network
|
s-cms
|
s-cms
|
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19046
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209445
|
6.5 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
|
CWE-22
Path Traversal
|
CVE-2020-18127
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209446
|
5.4 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18126
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209447
|
6.1 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18125
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209448
|
5.7 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
|
CWE-352
Origin Validation Error
|
CVE-2020-18124
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209449
|
6.5 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-18123
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209450
|
8.8 |
HIGH
Network
|
indexhibit
|
indexhibit
|
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-18121
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|