|
208871
|
6.5 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
|
CWE-22
Path Traversal
|
CVE-2020-18127
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208872
|
5.4 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18126
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208873
|
6.1 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18125
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208874
|
5.7 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
|
CWE-352
Origin Validation Error
|
CVE-2020-18124
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208875
|
6.5 |
MEDIUM
Network
|
indexhibit
|
indexhibit
|
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-18123
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208876
|
8.8 |
HIGH
Network
|
indexhibit
|
indexhibit
|
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-18121
|
2024-11-21 14:08 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208877
|
8.8 |
HIGH
Network
|
youdiancms
|
youdiancms
|
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-18116
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208878
|
9.8 |
CRITICAL
Network
|
dedecms
|
dedecms
|
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18114
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208879
|
9.8 |
CRITICAL
Network
|
wms_project
|
wms
|
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-18106
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208880
|
6.1 |
MEDIUM
Network
|
jupo
|
mezzanine
|
Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than …
|
CWE-79
Cross-site Scripting
|
CVE-2020-19002
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|