|
198171
|
5.4 |
MEDIUM
Network
|
pi-hole
|
pi-hole
|
Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35592
|
2024-11-21 14:27 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198172
|
5.4 |
MEDIUM
Network
|
pi-hole
|
pi-hole
|
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value …
|
CWE-384
Session Fixation
|
CVE-2020-35591
|
2024-11-21 14:27 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198173
|
6.5 |
MEDIUM
Network
|
endalia
|
selection_portal
|
In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file …
|
NVD-CWE-Other
|
CVE-2020-35577
|
2024-11-21 14:27 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198174
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server…
|
CWE-94
Code Injection
|
CVE-2020-35339
|
2024-11-21 14:27 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198175
|
5.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have be…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-35570
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198176
|
6.1 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35569
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198177
|
4.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response all…
|
CWE-200
Information Exposure
|
CVE-2020-35568
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198178
|
7.8 |
HIGH
Local
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-35567
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198179
|
5.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local Fil…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-35566
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198180
|
9.8 |
CRITICAL
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-35565
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|