2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-12838
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.

CVE-2020-13825
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, tvType, objID, catgID, objTypeID, or editMode parameter.

CVE-2020-10472
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

CVE-2020-15864
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.

CVE-2020-36079
Software Genérico Web
N/A
UNKNOWN
EPSS
15.6%
2020 2 PoCs

Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, for example, place a .php file in the server's uploaded/ directory. NOTE: the vendor disputes this because exploitation can only be performed by an admin who has "lots of other possibilities to harm a site.

CVE-2020-15694
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.

CVE-2020-18662
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVE-2020-15831
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.

CVE-2020-9390
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.

CVE-2020-13786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

CVE-2020-25955
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.

CVE-2020-13118
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

CVE-2020-26051
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.

CVE-2020-29607
Software Genérico Web
N/A
UNKNOWN
EPSS
76.9%
2020 6 PoCs

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

CVE-2020-23450
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.

CVE-2020-11985
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
15.3%
2020 CWE-345 1 PoC

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVE-2020-24194
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.

CVE-2020-10396
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-language.php by adding a question mark (?) followed by the payload.

CVE-2020-12280
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.

CVE-2020-10390
Software Genérico Web
N/A
UNKNOWN
EPSS
4.7%
2020 2 PoCs

OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by saving the code to be executed as the wkhtmltopdf path via admin/save-settings.php.