|
197941
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session …
|
CWE-79
Cross-site Scripting
|
CVE-2020-8115
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197942
|
9.8 |
CRITICAL
Network
|
phpabook_project
|
phpabook
|
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
|
CWE-287
Improper Authentication
|
CVE-2020-8510
|
2024-11-21 14:38 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197943
|
4.3 |
MEDIUM
Network
|
prototypejs
|
prototype
|
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
|
CWE-862
Missing Authorization
|
CVE-2020-7993
|
2024-11-21 14:38 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197944
|
9.8 |
CRITICAL
Network
|
norman
|
malware_cleaner
|
nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8508
|
2024-11-21 14:38 |
2020-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197945
|
6.1 |
MEDIUM
Network
|
maxum
|
rumpus
|
An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functiona…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8514
|
2024-11-21 14:38 |
2020-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197946
|
5.3 |
MEDIUM
Network
|
torproject
|
tor
|
The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to di…
|
NVD-CWE-noinfo
|
CVE-2020-8516
|
2024-11-21 14:38 |
2020-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197947
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor2960_firmware vigor300b_firmware vigor3900_firmware
|
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacter…
|
CWE-78
OS Command
|
CVE-2020-8515
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197948
|
6.1 |
MEDIUM
Network
|
icewarp
|
icewarp_server
|
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8512
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197949
|
6.5 |
MEDIUM
Network
|
arox
|
school_management_software_php\/mysql
|
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-8505
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197950
|
6.5 |
MEDIUM
Network
|
arox
|
school_management_software_php\/mysql
|
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
|
CWE-352
Origin Validation Error
|
CVE-2020-8504
|
2024-11-21 14:38 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|