|
208161
|
8.1 |
HIGH
Network
|
quadbase
|
espressdashboard
|
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrie…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-24985
|
2024-11-21 14:16 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208162
|
4.3 |
MEDIUM
Network
|
quadbase
|
espressdashboard
|
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their ac…
|
CWE-352
Origin Validation Error
|
CVE-2020-24982
|
2024-11-21 14:16 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208163
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
|
CWE-89
SQL Injection
|
CVE-2020-24877
|
2024-11-21 14:16 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208164
|
8.8 |
HIGH
Network
|
quadbase
|
espressreports_es
|
An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web …
|
CWE-352
Origin Validation Error
|
CVE-2020-24984
|
2024-11-21 14:16 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208165
|
8.8 |
HIGH
Network
|
quadbase
|
espressreports_es
|
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the targe…
|
CWE-352
Origin Validation Error
|
CVE-2020-24983
|
2024-11-21 14:16 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208166
|
9.8 |
CRITICAL
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or expl…
|
CWE-89
SQL Injection
|
CVE-2020-24791
|
2024-11-21 14:16 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208167
|
9.8 |
CRITICAL
Network
|
qcubed
|
qcubed
|
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to exec…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24914
|
2024-11-21 14:16 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208168
|
9.8 |
CRITICAL
Network
|
qcubed
|
qcubed
|
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a …
|
CWE-89
SQL Injection
|
CVE-2020-24913
|
2024-11-21 14:16 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208169
|
6.1 |
MEDIUM
Network
|
qcubed
|
qcubed
|
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authentica…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24912
|
2024-11-21 14:16 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208170
|
7.8 |
HIGH
Local
|
checkmk
|
checkmk
|
Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
|
NVD-CWE-Other
|
CVE-2020-24908
|
2024-11-21 14:16 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|