476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-10548
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-35848
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 2 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

CVE-2020-9483
Apache SkyWalking Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 2 PoCs

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.

CVE-2020-10546
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-10220
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 4 PoCs

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

CVE-2020-9547
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.3%
2020 7 PoCs

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

CVE-2020-27481
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.0%
2020 0 PoCs

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

CVE-2020-6637
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2020 1 PoC

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

CVE-2020-35847
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVE-2020-27615
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.3%
2020 3 PoCs

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-5777
MAGMI Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.7%
2020 1 PoC

MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done by sending at least 151 simultaneous requests to the Magento website to trigger a "Too many connections" error, then use default magmi:magmi basic authentication to remotely bypass authentication.

CVE-2020-22211
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-10547
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-11530
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 2 PoCs

A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

CVE-2020-13640
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.9%
2020 3 PoCs

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

CVE-2020-22208
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
32.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CVE-2020-22209
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
43.9%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

CVE-2020-26935
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2020 1 PoC

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

CVE-2020-5307
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2020 1 PoC

PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.