Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2020-20067: Bug: file upload vulnerability · Issue #1 · a932278490/ebcms

File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.

CVE
#vulnerability#git
CVE-2020-20413: WUZHICMS-SQL-Injection/README.md at master · SuperSalsa20/WUZHICMS-SQL-Injection

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

CVE-2020-20502: Denial of service attack caused by CSRF(CSRF造成的拒绝服务攻击) · Issue #27 · yzmcms/yzmcms

Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.

CVE-2020-20636

SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.

CVE-2020-20918: Pluck-4.7.10-dev2 admin background exists a remote command execution vulnerability when creating a new web page · Issue #80 · pluck-cms/pluck

An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.

CVE-2023-34600: Home - Adiscon LogAnalyzer

Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

CVE-2020-21400: i found admin/admin_save.php in PHPMyWind 5.6 has sql injection. · Issue #11 · gaozhifeng/PHPMyWind

SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.

CVE-2020-21474: File upload vulnerability in Nucleus CMS v3.71 · Issue #95 · NucleusCMS/NucleusCMS

File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.

CVE-2020-21268: A stored XSS vulnerability that leads to the capture of other people's cookies · Issue #40 · easysoft/zentaopms

Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.

CVE-2020-21486: PHPOK5.4 has sensitive information disclosure and sql injection · Issue #8 · qinggan/phpok

SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.