|
210701
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-23178
|
2024-11-21 14:13 |
2021-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210702
|
8.8 |
HIGH
Network
|
monstra
|
monstra_cms
|
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.
|
CWE-94
Code Injection
|
CVE-2020-23219
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210703
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Impor…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23217
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210704
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under …
|
CWE-79
Cross-site Scripting
|
CVE-2020-23214
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210705
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the …
|
CWE-79
Cross-site Scripting
|
CVE-2020-23209
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210706
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start …
|
CWE-79
Cross-site Scripting
|
CVE-2020-23208
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210707
|
5.4 |
MEDIUM
Network
|
phplist
|
phplist
|
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Conf…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23207
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210708
|
5.4 |
MEDIUM
Network
|
monstra
|
monstra_cms
|
A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23205
|
2024-11-21 14:13 |
2021-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210709
|
6.1 |
MEDIUM
Network
|
enhancesoft
|
osticket
|
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22609
|
2024-11-21 14:13 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210710
|
6.1 |
MEDIUM
Network
|
enhancesoft
|
osticket
|
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22608
|
2024-11-21 14:13 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|