|
208881
|
9.8 |
CRITICAL
Network
|
simiki_project
|
simiki
|
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
|
CWE-77
Command Injection
|
CVE-2020-19001
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208882
|
6.1 |
MEDIUM
Network
|
simiki_project
|
simiki
|
Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19000
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208883
|
6.1 |
MEDIUM
Network
|
blog_mini_project
|
blog_mini
|
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18999
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208884
|
6.1 |
MEDIUM
Network
|
blog_mini_project
|
blog_mini
|
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18998
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208885
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
|
CWE-89
SQL Injection
|
CVE-2020-18477
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208886
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
|
CWE-89
SQL Injection
|
CVE-2020-18476
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208887
|
5.4 |
MEDIUM
Network
|
hucart
|
hucart
|
Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other user…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18475
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208888
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18470
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208889
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18469
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208890
|
5.4 |
MEDIUM
Network
|
qdpm
|
qdpm
|
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP req…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18468
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|