1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-15052
Software Genérico Database
N/A
UNKNOWN
EPSS
9.1%
2020 1 PoC

An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.

CVE-2020-9318
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert settings in the UI. This is fixed in 9.2.15.

CVE-2020-15714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2020-18020
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.4%
2020 1 PoC

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

CVE-2020-26525
Software Genérico Web Database
N/A
UNKNOWN
EPSS
8.4%
2020 1 PoC

Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.

CVE-2020-12050
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.

CVE-2020-17506
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2020 3 PoCs

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

CVE-2020-27615
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.3%
2020 3 PoCs

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

CVE-2020-9315
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2020 1 PoC

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

CVE-2020-21808
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

CVE-2020-15051
Software Genérico Web Database
N/A
UNKNOWN
EPSS
25.8%
2020 1 PoC

An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields.

CVE-2020-28688
Software Genérico Web Database
N/A
UNKNOWN
EPSS
11.8%
2020 1 PoC

The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

CVE-2020-7014
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-266 1 PoC

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVE-2020-10803
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

CVE-2020-9327
Software Genérico Database
N/A
UNKNOWN
EPSS
1.0%
2020 5 PoCs

In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.

CVE-2020-23978
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

CVE-2020-15487
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote command execution is possible by using this SQL injection to update certain database values, which are then executed by a bizRule eval() function in the yii/framework/web/auth/CAuthManager.php file. Resultant authorization bypass is also possible, by recovering or modifying password hashes and password reset tokens, al

CVE-2020-5725
Grandstream UCM6200 series Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-89 2 PoCs

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-29284
Software Genérico Web Database
N/A
UNKNOWN
EPSS
21.6%
2020 2 PoCs

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.