|
209171
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18663
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209172
|
9.8 |
CRITICAL
Network
|
sir
|
gnuboard
|
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
|
CWE-89
SQL Injection
|
CVE-2020-18662
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209173
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18661
|
2024-11-21 14:08 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209174
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
|
CWE-601
Open Redirect
|
CVE-2020-18660
|
2024-11-21 14:08 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209175
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-18659
|
2024-11-21 14:08 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209176
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18658
|
2024-11-21 14:08 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209177
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18657
|
2024-11-21 14:08 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209178
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".
|
CWE-79
Cross-site Scripting
|
CVE-2020-18654
|
2024-11-21 14:08 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209179
|
8.8 |
HIGH
Network
|
juqingcms
|
juqingcms
|
Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.php?c=administrator&a=add".
|
CWE-352
Origin Validation Error
|
CVE-2020-18648
|
2024-11-21 14:08 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209180
|
7.5 |
HIGH
Network
|
5none
|
nonecms
|
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-18647
|
2024-11-21 14:08 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|