|
208361
|
7.5 |
HIGH
Network
|
unix4lyfe
|
darkhttpd
|
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-25691
|
2024-11-21 14:18 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208362
|
8.8 |
HIGH
Network
|
samba
|
samba
|
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued ticket…
|
CWE-20
Improper Input Validation
|
CVE-2020-25721
|
2024-11-21 14:18 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208363
|
8.8 |
HIGH
Network
|
samba debian fedoraproject canonical
|
samba debian_linux fedora ubuntu_linux
|
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
|
CWE-863
Incorrect Authorization
|
CVE-2020-25722
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208364
|
8.8 |
HIGH
Network
|
samba fedoraproject
|
samba fedora
|
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
|
CWE-862
Missing Authorization
|
CVE-2020-25718
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208365
|
7.2 |
HIGH
Network
|
samba debian fedoraproject canonical redhat
|
samba debian_linux fedora ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_for_scientific_computing enterprise_linux enterprise_linux_for_po…
|
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents …
|
CWE-362
Race Condition
|
CVE-2020-25719
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208366
|
8.1 |
HIGH
Network
|
samba debian fedoraproject redhat canonical
|
samba debian_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_for_scientific_computing enterprise_linux enterprise_linux_server enterprise_l…
|
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
|
CWE-20
Improper Input Validation
|
CVE-2020-25717
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208367
|
9.8 |
CRITICAL
Network
|
mobile_shop_system_project
|
mobile_shop_system
|
An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.
|
CWE-89
SQL Injection
|
CVE-2020-25905
|
2024-11-21 14:18 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208368
|
9.1 |
CRITICAL
Network
|
getsymphony
|
symphony
|
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
|
CWE-611
XXE
|
CVE-2020-25912
|
2024-11-21 14:18 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208369
|
9.1 |
CRITICAL
Network
|
modx
|
modx_revolution
|
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
|
CWE-611
XXE
|
CVE-2020-25911
|
2024-11-21 14:18 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208370
|
5.5 |
MEDIUM
Local
|
ranko
|
rkcms
|
A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=../../../../111.txt&filetype=image/jpeg of the master version of RKCMS. This vu…
|
CWE-22
Path Traversal
|
CVE-2020-25881
|
2024-11-21 14:18 |
2021-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|