|
210371
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10246
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210372
|
7.5 |
HIGH
Network
|
jpaseto_project
|
jpaseto
|
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-10244
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210373
|
5.5 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive da…
|
CWE-362
Race Condition
|
CVE-2020-10237
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210374
|
6.1 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause…
|
CWE-20
Improper Input Validation
|
CVE-2020-10236
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210375
|
8.8 |
HIGH
Network
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed …
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2020-10235
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210376
|
9.1 |
CRITICAL
Network
|
sleuthkit
|
the_sleuth_kit
|
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10233
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210377
|
9.8 |
CRITICAL
Network
|
sleuthkit debian fedoraproject
|
the_sleuth_kit debian_linux fedora
|
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10232
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210378
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
job_portal
|
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to uploa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10225
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210379
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
online_book_store
|
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10224
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210380
|
6.1 |
MEDIUM
Network
|
searchblox
|
searchblox
|
SearchBlox before Version 9.1 is vulnerable to cross-origin resource sharing misconfiguration.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10132
|
2024-11-21 13:54 |
2023-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|