|
208281
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Conf…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23207
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208282
|
5.4 |
MEDIUM
Network
|
monstra
|
monstra_cms
|
A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23205
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208283
|
6.1 |
MEDIUM
Network
|
enhancesoft
|
osticket
|
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22609
|
2024-11-21 14:13 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208284
|
6.1 |
MEDIUM
Network
|
enhancesoft
|
osticket
|
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22608
|
2024-11-21 14:13 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208285
|
6.1 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22607
|
2024-11-21 14:13 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208286
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sen…
|
CWE-287 CWE-862
Improper Authentication Missing Authorization
|
CVE-2020-22176
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208287
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain…
|
CWE-89
SQL Injection
|
CVE-2020-22175
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208288
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensiti…
|
CWE-89
SQL Injection
|
CVE-2020-22174
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208289
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive i…
|
CWE-89
SQL Injection
|
CVE-2020-22173
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208290
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive inf…
|
CWE-89
SQL Injection
|
CVE-2020-22172
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|