|
209391
|
7.2 |
HIGH
Network
|
rgcms_project
|
rgcms
|
An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21481
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209392
|
7.2 |
HIGH
Network
|
rgcms_project
|
rgcms
|
An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.
|
NVD-CWE-noinfo
|
CVE-2020-21480
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209393
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21322
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209394
|
4.3 |
MEDIUM
Network
|
emlog
|
emlog
|
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
|
CWE-352
Origin Validation Error
|
CVE-2020-21321
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209395
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
|
CWE-89
SQL Injection
|
CVE-2020-21127
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209396
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
|
CWE-352
Origin Validation Error
|
CVE-2020-21126
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209397
|
9.8 |
CRITICAL
Network
|
ureport_project
|
ureport
|
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2020-21125
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209398
|
9.8 |
CRITICAL
Network
|
ureport_project
|
ureport
|
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
|
CWE-863
Incorrect Authorization
|
CVE-2020-21124
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209399
|
5.3 |
MEDIUM
Network
|
ureport_project
|
ureport
|
UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21122
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209400
|
9.8 |
CRITICAL
Network
|
kliqqi
|
kliqqi_cms
|
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.
|
CWE-89
SQL Injection
|
CVE-2020-21121
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|