|
208811
|
8.8 |
HIGH
Network
|
zzzcms
|
zzzcms
|
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-19682
|
2024-11-21 14:09 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208812
|
6.1 |
MEDIUM
Network
|
racktables_project
|
racktables
|
Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19611
|
2024-11-21 14:09 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208813
|
6.5 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.
|
CWE-352
Origin Validation Error
|
CVE-2020-19964
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208814
|
5.4 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19962
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208815
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.
|
CWE-89
SQL Injection
|
CVE-2020-19961
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208816
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.
|
CWE-89
SQL Injection
|
CVE-2020-19960
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208817
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.
|
CWE-89
SQL Injection
|
CVE-2020-19959
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208818
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
|
CWE-89
SQL Injection
|
CVE-2020-19957
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208819
|
7.5 |
HIGH
Network
|
s-cms
|
s-cms
|
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
|
CWE-611
XXE
|
CVE-2020-19954
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208820
|
8.8 |
HIGH
Network
|
yzmcms
|
yzmcms
|
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
|
CWE-352
Origin Validation Error
|
CVE-2020-19951
|
2024-11-21 14:09 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|