|
209121
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhicms
|
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19551
|
2024-11-21 14:09 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209122
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19915
|
2024-11-21 14:09 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209123
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19295
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209124
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comm…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19294
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209125
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19293
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209126
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19292
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209127
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19291
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209128
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment …
|
CWE-79
Cross-site Scripting
|
CVE-2020-19290
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209129
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new alb…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19289
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209130
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19288
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|