|
209521
|
6.1 |
MEDIUM
Network
|
pix-link
|
lv-wr07_firmware
|
XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as d…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24104
|
2024-11-21 14:14 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209522
|
6.1 |
MEDIUM
Network
|
mara_cms_project
|
mara_cms
|
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24223
|
2024-11-21 14:14 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209523
|
9.8 |
CRITICAL
Network
|
projectworlds
|
travel_management_system
|
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain…
|
CWE-434 CWE-425
Unrestricted Upload of File with Dangerous Type Direct Request ('Forced Browsing')
|
CVE-2020-24203
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209524
|
9.8 |
CRITICAL
Network
|
projectworlds
|
house_rental_and_property_listing_project
|
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24202
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209525
|
7.2 |
HIGH
Network
|
online_bike_rental_project
|
online_bike_rental
|
An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-24196
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209526
|
6.1 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication stored XSS during login/logout logs recording.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24390
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209527
|
5.4 |
MEDIUM
Network
|
online_hotel_booking_system_pro_project
|
online_hotel_booking_system_pro
|
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23984
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209528
|
5.4 |
MEDIUM
Network
|
ichat_project
|
ichat
|
Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23983
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209529
|
6.1 |
MEDIUM
Network
|
designmasterevents
|
conference_management_cms
|
DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
|
CWE-79
Cross-site Scripting
|
CVE-2020-23982
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209530
|
6.1 |
MEDIUM
Network
|
13enforme
|
13enforme_cms
|
13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23981
|
2024-11-21 14:14 |
2020-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|