|
209151
|
6.5 |
MEDIUM
Network
|
thinkcmf
|
thinkcmf
|
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2020-18151
|
2024-11-21 14:08 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209152
|
6.1 |
MEDIUM
Network
|
baidu
|
umeditor
|
Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18145
|
2024-11-21 14:08 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209153
|
9.8 |
CRITICAL
Network
|
ectouch
|
ectouch
|
SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
|
CWE-89
SQL Injection
|
CVE-2020-18144
|
2024-11-21 14:08 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209154
|
9.8 |
CRITICAL
Network
|
wms_project
|
wms
|
SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".
|
CWE-89
SQL Injection
|
CVE-2020-18544
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209155
|
9.1 |
CRITICAL
Network
|
halo
|
halo
|
File Deletion vulnerability in Halo 0.4.3 via delBackup.
|
CWE-862
Missing Authorization
|
CVE-2020-19038
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209156
|
5.3 |
MEDIUM
Network
|
halo
|
halo
|
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
|
CWE-287
Improper Authentication
|
CVE-2020-19037
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209157
|
5.4 |
MEDIUM
Network
|
halo
|
halo
|
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18982
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209158
|
9.8 |
CRITICAL
Network
|
halo
|
halo
|
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
|
NVD-CWE-noinfo
|
CVE-2020-18980
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209159
|
6.1 |
MEDIUM
Network
|
halo
|
halo
|
Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18979
|
2024-11-21 14:08 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209160
|
5.3 |
MEDIUM
Network
|
thinksaas
|
thinksaas
|
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app…
|
NVD-CWE-Other
|
CVE-2020-18741
|
2024-11-21 14:08 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|