|
208611
|
6.5 |
MEDIUM
Network
|
libiec_iccp_mod_project
|
libiec_iccp_mod
|
libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_connection.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20663
|
2024-11-21 14:12 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208612
|
6.5 |
MEDIUM
Network
|
libiec_iccp_mod_project
|
libiec_iccp_mod
|
libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_example1.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20662
|
2024-11-21 14:12 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208613
|
5.4 |
MEDIUM
Network
|
ucms_project
|
ucms
|
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20781
|
2024-11-21 14:12 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208614
|
5.4 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20696
|
2024-11-21 14:12 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208615
|
5.4 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20695
|
2024-11-21 14:12 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208616
|
8.8 |
HIGH
Network
|
gilacms
|
gila_cms
|
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-20693
|
2024-11-21 14:12 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208617
|
7.2 |
HIGH
Network
|
gilacms
|
gila_cms
|
GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.
|
CWE-89
SQL Injection
|
CVE-2020-20692
|
2024-11-21 14:12 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208618
|
6.5 |
MEDIUM
Network
|
monstra
|
monstra_cms
|
An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20691
|
2024-11-21 14:12 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208619
|
8.1 |
HIGH
Network
|
maccms
|
maccms
|
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
|
CWE-352
Origin Validation Error
|
CVE-2020-20514
|
2024-11-21 14:12 |
2021-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208620
|
6.1 |
MEDIUM
Network
|
shopkit_project
|
shopkit
|
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20508
|
2024-11-21 14:12 |
2021-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|