|
210141
|
7.2 |
HIGH
Network
|
wso2
|
identity_server_analytics identity_server identity_server_as_key_manager enterprise_integrator api_microgateway api_manager_analytics api_manager
|
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0…
|
CWE-611
XXE
|
CVE-2020-12719
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210142
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypass…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12718
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210143
|
6.1 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. N…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12708
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210144
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
lepton_cms
|
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12707
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210145
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12706
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210146
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12705
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210147
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has PageController stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12704
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210148
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has XSS during PackageController uninstall.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12703
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210149
|
6.1 |
MEDIUM
Network
|
mitel
|
shoretel_conference_web mivoice_connect
|
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12679
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210150
|
6.5 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-12687
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|