|
196241
|
4.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
|
CWE-20
Improper Input Validation
|
CVE-2020-8122
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196242
|
8.1 |
HIGH
Network
|
nextcloud
|
nextcloud_server
|
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-8121
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196243
|
6.1 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8120
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196244
|
4.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
|
CWE-863
Incorrect Authorization
|
CVE-2020-8119
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196245
|
5.0 |
MEDIUM
Network
|
nextcloud novell opensuse
|
nextcloud_server suse_linux_enterprise_server backports_sle
|
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8118
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196246
|
4.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-8117
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196247
|
7.3 |
HIGH
Network
|
dot-prop_project
|
dot-prop
|
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as …
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-8116
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196248
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session …
|
CWE-79
Cross-site Scripting
|
CVE-2020-8115
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196249
|
9.8 |
CRITICAL
Network
|
phpabook_project
|
phpabook
|
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
|
CWE-287
Improper Authentication
|
CVE-2020-8510
|
2024-11-21 14:38 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196250
|
4.3 |
MEDIUM
Network
|
prototypejs
|
prototype
|
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
|
CWE-862
Missing Authorization
|
CVE-2020-7993
|
2024-11-21 14:38 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|