|
209121
|
3.5 |
LOW
Network
|
aikcms
|
aikcms
|
Cross Site Request Forgery (CSRF) vulnerability in AikCms 2.0.0 in video_list.php, which can let a malicious user delete movie information.
|
CWE-352
Origin Validation Error
|
CVE-2020-18464
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209122
|
2.4 |
LOW
Network
|
aikcms
|
aikcms
|
Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delete a video message.
|
CWE-352
Origin Validation Error
|
CVE-2020-18463
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209123
|
7.2 |
HIGH
Network
|
aikcms
|
aikcms
|
File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18462
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209124
|
8.8 |
HIGH
Network
|
711cms
|
711cms
|
Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.
|
CWE-352
Origin Validation Error
|
CVE-2020-18460
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209125
|
8.0 |
HIGH
Network
|
damicms
|
damicms
|
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
|
CWE-352
Origin Validation Error
|
CVE-2020-18458
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209126
|
6.8 |
MEDIUM
Network
|
bycms_project
|
bycms
|
Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.
|
CWE-352
Origin Validation Error
|
CVE-2020-18457
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209127
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18456
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209128
|
4.8 |
MEDIUM
Network
|
bycms_project
|
bycms
|
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18455
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209129
|
6.8 |
MEDIUM
Network
|
bycms_project
|
bycms
|
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
|
CWE-352
Origin Validation Error
|
CVE-2020-18454
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209130
|
4.8 |
MEDIUM
Network
|
damicms
|
damicms
|
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18451
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|