|
199281
|
6.5 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
|
CWE-352
Origin Validation Error
|
CVE-2020-35759
|
2024-11-21 14:28 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199282
|
6.5 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
|
CWE-22
Path Traversal
|
CVE-2020-36142
|
2024-11-21 14:28 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199283
|
8.8 |
HIGH
Network
|
bloofox
|
bloofoxcms
|
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-36141
|
2024-11-21 14:28 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199284
|
6.5 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
|
CWE-352
Origin Validation Error
|
CVE-2020-36140
|
2024-11-21 14:28 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199285
|
5.4 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36139
|
2024-11-21 14:28 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199286
|
7.5 |
HIGH
Network
|
obottle_project
|
obottle
|
OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
|
NVD-CWE-noinfo
|
CVE-2020-36009
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199287
|
8.1 |
HIGH
Network
|
obottle_project
|
obottle
|
OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
|
NVD-CWE-noinfo
|
CVE-2020-36008
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199288
|
6.1 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36007
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199289
|
6.5 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
|
NVD-CWE-noinfo
|
CVE-2020-36006
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199290
|
6.5 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
|
NVD-CWE-noinfo
|
CVE-2020-36005
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|