|
209691
|
6.1 |
MEDIUM
Network
|
qibosoft
|
qibocms
|
Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18022
|
2024-11-21 14:08 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209692
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
|
CWE-79
Cross-site Scripting
|
CVE-2020-17999
|
2024-11-21 14:08 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209693
|
9.8 |
CRITICAL
Network
|
phpshe
|
mall_system
|
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" compo…
|
CWE-89
SQL Injection
|
CVE-2020-18020
|
2024-11-21 14:08 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209694
|
7.5 |
HIGH
Network
|
xinfu
|
oa_system
|
SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "m…
|
CWE-89
SQL Injection
|
CVE-2020-18019
|
2024-11-21 14:08 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209695
|
7.5 |
HIGH
Network
|
apache
|
ozone
|
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl comma…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-17517
|
2024-11-21 14:08 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209696
|
5.4 |
MEDIUM
Network
|
dotcms
|
dotcms
|
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17542
|
2024-11-21 14:08 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209697
|
9.1 |
CRITICAL
Network
|
feifeicms
|
feifeicms
|
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component.
|
CWE-22
Path Traversal
|
CVE-2020-17564
|
2024-11-21 14:08 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209698
|
9.1 |
CRITICAL
Network
|
feifeicms
|
feifeicms
|
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=".
|
CWE-22
Path Traversal
|
CVE-2020-17563
|
2024-11-21 14:08 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209699
|
6.1 |
MEDIUM
Network
|
wso2
|
identity_server_as_key_manager enterprise_integrator api_microgateway identity_server api_manager_analytics identity_server_analytics micro_integrator api_manager
|
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-17453
|
2024-11-21 14:08 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209700
|
5.4 |
MEDIUM
Network
|
fujitsu
|
serverview_remote_management
|
Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17457
|
2024-11-21 14:08 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|