|
218591
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
lepton_cms
|
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12707
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218592
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12706
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218593
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12705
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218594
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has PageController stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12704
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218595
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has XSS during PackageController uninstall.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12703
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218596
|
6.1 |
MEDIUM
Network
|
mitel
|
shoretel_conference_web mivoice_connect
|
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12679
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218597
|
6.5 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-12687
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218598
|
5.4 |
MEDIUM
Network
|
katyshop2_project
|
katyshop2
|
Katyshop2 before 2.12 has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12683
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218599
|
6.1 |
MEDIUM
Network
|
iframe_project
|
iframe
|
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12696
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218600
|
5.4 |
MEDIUM
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
|
CWE-347 CWE-294
Improper Verification of Cryptographic Signature Authentication Bypass by Capture-replay
|
CVE-2020-12692
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|