|
209231
|
8.1 |
HIGH
Network
|
jflyfox
|
jfinal_cms
|
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component …
|
CWE-22
Path Traversal
|
CVE-2020-19150
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209232
|
5.4 |
MEDIUM
Network
|
jflyfox
|
jfinal_cms
|
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19148
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209233
|
6.5 |
MEDIUM
Network
|
jflyfox
|
jfinal_cms
|
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java…
|
CWE-22
Path Traversal
|
CVE-2020-19147
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209234
|
6.5 |
MEDIUM
Network
|
jflyfox
|
jfinal_cms
|
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
|
CWE-22
Path Traversal
|
CVE-2020-19146
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209235
|
6.5 |
MEDIUM
Network
|
simplesystems debian netapp
|
libtiff debian_linux ontap_select_deploy_administration_utility
|
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19144
|
2024-11-21 14:08 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209236
|
6.5 |
MEDIUM
Network
|
simplesystems debian
|
libtiff debian_linux
|
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19143
|
2024-11-21 14:08 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209237
|
9.8 |
CRITICAL
Network
|
dotcms
|
dotcms
|
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19138
|
2024-11-21 14:08 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209238
|
7.5 |
HIGH
Network
|
autumn_project
|
autumn
|
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-19137
|
2024-11-21 14:08 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209239
|
7.5 |
HIGH
Network
|
simplesystems debian
|
libtiff debian_linux
|
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19131
|
2024-11-21 14:08 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209240
|
9.8 |
CRITICAL
Network
|
bertanddip
|
craigms
|
An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.
|
CWE-77
Command Injection
|
CVE-2020-18048
|
2024-11-21 14:08 |
2021-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|