|
211091
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20349
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211092
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20348
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211093
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20347
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211094
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20345
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211095
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20344
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211096
|
6.5 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator backgro…
|
CWE-352
Origin Validation Error
|
CVE-2020-20343
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211097
|
7.5 |
HIGH
Network
|
yzmcms
|
yzmcms
|
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-20341
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211098
|
7.5 |
HIGH
Network
|
s-cms
|
s-cms
|
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-20340
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211099
|
9.1 |
CRITICAL
Network
|
bludit
|
bludit
|
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
|
NVD-CWE-noinfo
|
CVE-2020-20495
|
2024-11-21 14:12 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211100
|
7.5 |
HIGH
Network
|
libiec_iccp_mod_project
|
libiec_iccp_mod
|
A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20490
|
2024-11-21 14:12 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|