|
209281
|
8.8 |
HIGH
Network
|
microsoft
|
internet_explorer
|
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated …
|
NVD-CWE-noinfo
|
CVE-2020-1012
|
2024-11-21 14:09 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209282
|
7.2 |
HIGH
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_content'] is file content, there is no filter function for se…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19891
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209283
|
4.9 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2020-19890
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209284
|
8.8 |
HIGH
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-19889
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209285
|
5.9 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a ta…
|
CWE-287
Improper Authentication
|
CVE-2020-19888
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209286
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19887
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209287
|
8.1 |
HIGH
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
|
CWE-352
Origin Validation Error
|
CVE-2020-19886
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209288
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19885
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209289
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19884
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209290
|
4.8 |
MEDIUM
Network
|
dbhcms_project
|
dbhcms
|
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19883
|
2024-11-21 14:09 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|