|
208551
|
5.4 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20946
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208552
|
8.8 |
HIGH
Network
|
qibosoft
|
qibosoft
|
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-20945
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208553
|
9.1 |
CRITICAL
Network
|
qibosoft
|
qibosoft
|
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
|
CWE-22
Path Traversal
|
CVE-2020-20944
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208554
|
4.3 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.
|
CWE-352
Origin Validation Error
|
CVE-2020-20943
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208555
|
6.1 |
MEDIUM
Network
|
personal_blog_cms_project
|
personal_blog_cms
|
Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20605
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208556
|
9.8 |
CRITICAL
Network
|
thinkcmf
|
thinkcmf
|
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
|
CWE-94
Code Injection
|
CVE-2020-20601
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208557
|
5.4 |
MEDIUM
Network
|
metinfo
|
metinfo
|
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20600
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208558
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20598
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208559
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20597
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208560
|
6.5 |
MEDIUM
Network
|
opms_project
|
opms
|
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
|
CWE-352
Origin Validation Error
|
CVE-2020-20595
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|