|
210301
|
5.4 |
MEDIUM
Network
|
munkireport_project
|
comment
|
A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15885
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210302
|
8.8 |
HIGH
Network
|
munkireport_project
|
munkireport
|
A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /datatables/data.
|
CWE-89
SQL Injection
|
CVE-2020-15884
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210303
|
6.1 |
MEDIUM
Network
|
managedinstalls_project
|
managedinstalls
|
A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (thr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15883
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210304
|
8.1 |
HIGH
Network
|
munkireport_project
|
munkireport
|
A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database.
|
CWE-352
Origin Validation Error
|
CVE-2020-15882
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210305
|
6.1 |
MEDIUM
Network
|
munki_facts_project
|
munki_facts
|
A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the key name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15881
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210306
|
8.8 |
HIGH
Network
|
embedthis
|
goahead
|
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via c…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-15688
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210307
|
7.5 |
HIGH
Network
|
cauldrondevelopment
|
c\!
|
tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.
|
CWE-22
Path Traversal
|
CVE-2020-15908
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210308
|
7.8 |
HIGH
Local
|
pypi
|
bsdiff4
|
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15904
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210309
|
6.1 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15902
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210310
|
8.8 |
HIGH
Network
|
nagios
|
nagios_xi
|
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
|
NVD-CWE-noinfo
|
CVE-2020-15901
|
2024-11-21 14:06 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|