|
209941
|
7.5 |
HIGH
Network
|
zblogcn
|
z-blogphp
|
Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_inp…
|
NVD-CWE-Other
|
CVE-2020-23352
|
2024-11-21 14:13 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209942
|
7.5 |
HIGH
Network
|
newbee-mall_project
|
newbee-mall
|
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information t…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-23449
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209943
|
9.8 |
CRITICAL
Network
|
newbee-mall_project
|
newbee-mall
|
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code…
|
CWE-306 CWE-706
Missing Authentication for Critical Function Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-23448
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209944
|
6.1 |
MEDIUM
Network
|
newbee-mall_project
|
newbee-mall
|
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23447
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209945
|
9.8 |
CRITICAL
Network
|
mingsoft
|
mcms
|
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
|
CWE-89
SQL Injection
|
CVE-2020-23262
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209946
|
7.5 |
HIGH
Network
|
pyres
|
termod4_firmware
|
Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-23162
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209947
|
6.5 |
MEDIUM
Network
|
pyres
|
termod4_firmware
|
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu a…
|
CWE-22
Path Traversal
|
CVE-2020-23161
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209948
|
8.8 |
HIGH
Network
|
pyres
|
termod4_firmware
|
Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.
|
NVD-CWE-noinfo
|
CVE-2020-23160
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209949
|
5.4 |
MEDIUM
Network
|
apfell_project
|
apfell
|
APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user sessi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23014
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209950
|
7.2 |
HIGH
Network
|
feehi
|
feehi_cms
|
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to pote…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22643
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|