|
209471
|
7.5 |
HIGH
Network
|
8cms
|
ljcms
|
A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-20583
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209472
|
7.5 |
HIGH
Network
|
mipcms
|
mipcms
|
A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-20582
|
2024-11-21 14:12 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209473
|
8.8 |
HIGH
Network
|
crmeb
|
crmeb
|
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
|
CWE-89
SQL Injection
|
CVE-2020-21394
|
2024-11-21 14:12 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209474
|
6.1 |
MEDIUM
Network
|
ipfire
|
ipfire
|
Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21142
|
2024-11-21 14:12 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209475
|
6.1 |
MEDIUM
Network
|
shopex
|
ecshop
|
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20640
|
2024-11-21 14:12 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209476
|
9.8 |
CRITICAL
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21786
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209477
|
8.8 |
HIGH
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
|
CWE-77
Command Injection
|
CVE-2020-21785
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209478
|
9.8 |
CRITICAL
Network
|
phpwcms
|
phpwcms
|
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
|
CWE-94
Code Injection
|
CVE-2020-21784
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209479
|
6.1 |
MEDIUM
Network
|
ibos
|
ibos
|
In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21783
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209480
|
4.3 |
MEDIUM
Network
|
crmeb
|
crmeb
|
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21788
|
2024-11-21 14:12 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|