|
209671
|
4.8 |
MEDIUM
Network
|
laobancms
|
laobancms
|
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".
|
CWE-79
Cross-site Scripting
|
CVE-2020-18167
|
2024-11-21 14:08 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209672
|
9.8 |
CRITICAL
Network
|
laobancms
|
laobancms
|
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18166
|
2024-11-21 14:08 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209673
|
4.8 |
MEDIUM
Network
|
laobancms
|
laobancms
|
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
|
CWE-79
Cross-site Scripting
|
CVE-2020-18165
|
2024-11-21 14:08 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209674
|
8.8 |
HIGH
Network
|
forestblog_project
|
forestblog
|
Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.
|
CWE-352
Origin Validation Error
|
CVE-2020-18964
|
2024-11-21 14:08 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209675
|
6.1 |
MEDIUM
Network
|
hotels_server_project
|
hotels_server
|
Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php".
|
CWE-79
Cross-site Scripting
|
CVE-2020-18102
|
2024-11-21 14:08 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209676
|
9.8 |
CRITICAL
Network
|
puppycms
|
puppycms
|
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-18890
|
2024-11-21 14:08 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209677
|
7.5 |
HIGH
Network
|
puppycms
|
puppycms
|
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
|
CWE-862
Missing Authorization
|
CVE-2020-18888
|
2024-11-21 14:08 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209678
|
6.5 |
MEDIUM
Network
|
puppycms
|
puppycms
|
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-18889
|
2024-11-21 14:08 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209679
|
9.8 |
CRITICAL
Network
|
projectworlds
|
online_book_store_project_in_php
|
SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2020-19114
|
2024-11-21 14:08 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209680
|
9.8 |
CRITICAL
Network
|
projectworlds
|
online_book_store_project_in_php
|
Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19113
|
2024-11-21 14:08 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|