|
208951
|
5.4 |
MEDIUM
Network
|
dotcms
|
dotcms
|
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17542
|
2024-11-21 14:08 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208952
|
9.1 |
CRITICAL
Network
|
feifeicms
|
feifeicms
|
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component.
|
CWE-22
Path Traversal
|
CVE-2020-17564
|
2024-11-21 14:08 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208953
|
9.1 |
CRITICAL
Network
|
feifeicms
|
feifeicms
|
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=".
|
CWE-22
Path Traversal
|
CVE-2020-17563
|
2024-11-21 14:08 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208954
|
6.1 |
MEDIUM
Network
|
wso2
|
identity_server_as_key_manager enterprise_integrator api_microgateway identity_server api_manager_analytics identity_server_analytics micro_integrator api_manager
|
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17453
|
2024-11-21 14:08 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208955
|
5.4 |
MEDIUM
Network
|
fujitsu
|
serverview_remote_management
|
Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17457
|
2024-11-21 14:08 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208956
|
7.5 |
HIGH
Network
|
apache debian
|
subversion debian_linux
|
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repositor…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-17525
|
2024-11-21 14:08 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208957
|
8.8 |
HIGH
Network
|
phpshe
|
phpshe
|
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2020-18215
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208958
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in t…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-17436
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208959
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in t…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-17435
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208960
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in t…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-17434
|
2024-11-21 14:08 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|