|
209911
|
9.8 |
CRITICAL
Network
|
koa2-blog_project
|
koa2-blog
|
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
|
CWE-89
SQL Injection
|
CVE-2020-21180
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209912
|
9.8 |
CRITICAL
Network
|
koa2-blog_project
|
koa2-blog
|
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.
|
CWE-89
SQL Injection
|
CVE-2020-21179
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209913
|
9.8 |
CRITICAL
Network
|
thinkjs
|
thinkjs
|
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
|
CWE-89
SQL Injection
|
CVE-2020-21176
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209914
|
9.8 |
CRITICAL
Network
|
cmswing
|
cmswing
|
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2020-20296
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209915
|
9.8 |
CRITICAL
Network
|
cmswing
|
cmswing
|
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2020-20295
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209916
|
9.8 |
CRITICAL
Network
|
cmswing
|
cmswing
|
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
|
CWE-89
SQL Injection
|
CVE-2020-20294
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209917
|
7.5 |
HIGH
Network
|
yccms
|
yccms
|
Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability.
|
CWE-22
Path Traversal
|
CVE-2020-20290
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209918
|
9.8 |
CRITICAL
Network
|
yccms
|
yccms
|
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
|
CWE-89
SQL Injection
|
CVE-2020-20289
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209919
|
4.8 |
MEDIUM
Network
|
rockoa
|
rockoa
|
RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/inp…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21147
|
2024-11-21 14:12 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209920
|
6.1 |
MEDIUM
Network
|
feehi
|
feehi_cms
|
Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21146
|
2024-11-21 14:12 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|