|
211901
|
8.8 |
HIGH
Network
|
open-emr phpgacl_project
|
openemr phpgacl
|
SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability In admin/edit_gr…
|
CWE-89
SQL Injection
|
CVE-2020-13566
|
2024-11-21 14:01 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211902
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attack…
|
CWE-89
SQL Injection
|
CVE-2020-13592
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211903
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An…
|
CWE-89
SQL Injection
|
CVE-2020-13591
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211904
|
8.8 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. A…
|
CWE-89
SQL Injection
|
CVE-2020-13587
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211905
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges w…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13534
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211906
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attac…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13533
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211907
|
7.8 |
HIGH
Local
|
dreamreport
|
dream_report
|
A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13532
|
2024-11-21 14:01 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211908
|
8.1 |
HIGH
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
|
CWE-862
Missing Authorization
|
CVE-2020-13422
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211909
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
|
NVD-CWE-Other
|
CVE-2020-13421
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211910
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
|
NVD-CWE-noinfo
|
CVE-2020-13420
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|