|
209291
|
7.5 |
HIGH
Network
|
jeecg
|
jeecg
|
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-20948
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209292
|
5.4 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20946
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209293
|
8.8 |
HIGH
Network
|
qibosoft
|
qibosoft
|
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.
|
CWE-352
Origin Validation Error
|
CVE-2020-20945
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209294
|
9.1 |
CRITICAL
Network
|
qibosoft
|
qibosoft
|
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
|
CWE-22
Path Traversal
|
CVE-2020-20944
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209295
|
4.3 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.
|
CWE-352
Origin Validation Error
|
CVE-2020-20943
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209296
|
6.1 |
MEDIUM
Network
|
personal_blog_cms_project
|
personal_blog_cms
|
Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20605
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209297
|
9.8 |
CRITICAL
Network
|
thinkcmf
|
thinkcmf
|
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
|
CWE-94
Code Injection
|
CVE-2020-20601
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209298
|
5.4 |
MEDIUM
Network
|
metinfo
|
metinfo
|
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20600
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209299
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20598
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209300
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20597
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|