|
209551
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attack…
|
CWE-89
SQL Injection
|
CVE-2020-13592
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209552
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An…
|
CWE-89
SQL Injection
|
CVE-2020-13591
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209553
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. A…
|
CWE-89
SQL Injection
|
CVE-2020-13587
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209554
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges w…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13534
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209555
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attac…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13533
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209556
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13532
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209557
|
8.1 |
HIGH
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
|
CWE-862
Missing Authorization
|
CVE-2020-13422
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209558
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
|
NVD-CWE-Other
|
CVE-2020-13421
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209559
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
|
NVD-CWE-noinfo
|
CVE-2020-13420
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209560
|
5.3 |
MEDIUM
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
|
CWE-22
Path Traversal
|
CVE-2020-13419
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|