|
210121
|
9.1 |
CRITICAL
Network
|
wdja
|
wdja_cms
|
WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php.
|
NVD-CWE-noinfo
|
CVE-2020-21648
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210122
|
6.1 |
MEDIUM
Network
|
waimai_super_cms_project
|
waimai_super_cms
|
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21506
|
2024-11-21 14:12 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210123
|
6.1 |
MEDIUM
Network
|
waimai_super_cms_project
|
waimai_super_cms
|
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21505
|
2024-11-21 14:12 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210124
|
6.1 |
MEDIUM
Network
|
waimai_super_cms_project
|
waimai_super_cms
|
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=login.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21504
|
2024-11-21 14:12 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210125
|
7.5 |
HIGH
Network
|
waimai_super_cms_project
|
waimai_super_cms
|
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parame…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-21503
|
2024-11-21 14:12 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210126
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21496
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210127
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21495
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210128
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21494
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210129
|
5.3 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
|
NVD-CWE-noinfo
|
CVE-2020-21493
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210130
|
5.4 |
MEDIUM
Network
|
maccms
|
maccms
|
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21434
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|