|
195991
|
7.2 |
HIGH
Network
|
red-gate
|
sql_monitor
|
Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert settings in the UI. This is fixed in 9.2.15.
|
CWE-89
SQL Injection
|
CVE-2020-9318
|
2024-11-21 14:40 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195992
|
7.5 |
HIGH
Network
|
golang debian
|
package_ssh debian_linux
|
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accept…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-9283
|
2024-11-21 14:40 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195993
|
8.8 |
HIGH
Network
|
proftpd debian fedoraproject opensuse siemens
|
proftpd debian_linux fedora leap backports_sle simatic_net_cp_1545-1_firmware simatic_net_cp_1543-1_firmware
|
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
|
CWE-416
Use After Free
|
CVE-2020-9273
|
2024-11-21 14:40 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195994
|
7.5 |
HIGH
Network
|
proftpd siemens opensuse
|
proftpd simatic_net_cp_1543-1_firmware simatic_net_cp_1545-1_firmware leap backports_sle
|
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9272
|
2024-11-21 14:40 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195995
|
8.8 |
HIGH
Network
|
libarchive canonical fedoraproject
|
libarchive ubuntu_linux fedora
|
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unsp…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9308
|
2024-11-21 14:40 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195996
|
6.5 |
MEDIUM
Network
|
icehrm
|
icehrm
|
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9271
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195997
|
8.8 |
HIGH
Network
|
icehrm
|
icehrm
|
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9270
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195998
|
7.2 |
HIGH
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.
|
CWE-89
SQL Injection
|
CVE-2020-9269
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195999
|
7.5 |
HIGH
Network
|
soplanning
|
soplanning
|
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
|
CWE-89
SQL Injection
|
CVE-2020-9268
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196000
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-9267
|
2024-11-21 14:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|