CVE-2020-23000 to CVE-2020-23999
158 CVEs with public proof-of-concept exploits.
- CVE-2020-230141 PoCAPfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback…
- CVE-2020-230151 PoCAn open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can…
- CVE-2020-230361 PoCMEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the…
- CVE-2020-230371 PoCPortable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary…
- CVE-2020-230381 PoCSwift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This…
- CVE-2020-230391 PoCFolder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder function under the…
- CVE-2020-230401 PoCSky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files…
- CVE-2020-230411 PoCDropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the…
- CVE-2020-230421 PoCDropouts Technologies LLP Super Backup v2.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter…
- CVE-2020-230431 PoCTran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows…
- CVE-2020-230441 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the…
- CVE-2020-230451 PoCMacrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId'…
- CVE-2020-230461 PoCDedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the…
- CVE-2020-230471 PoCMacrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the…
- CVE-2020-230481 PoCSeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via…
- CVE-2020-230491 PoCFork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field…
- CVE-2020-230501 PoCTAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of…
- CVE-2020-230511 PoCPhpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS)…
- CVE-2020-230521 PoCCatalyst IT Ltd Mahara CMS v19.10.2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component…
- CVE-2020-230541 PoCA cross-site scripting (XSS) vulnerability in NSK User Agent String Switcher Service v0.3.5 allows attackers to execute arbitrary web…
- CVE-2020-230551 PoCANCOM WLAN Controller (Wireless Series & Hotspot) WLC-1000 & WLC-4006 was discovered to contain multiple cross-site scripting (XSS)…
- CVE-2020-230581 PoCAn issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
- CVE-2020-230601 PoCInternet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability…
- CVE-2020-230611 PoCDropouts Technologies LLP Super Backup v2.0.5 was discovered to contain an issue in the path parameter of the `list` and `download` module…
- CVE-2020-230691 PoCPath Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read…
- CVE-2020-231091 PoCBuffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a…
- CVE-2020-231272 PoCsChamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
- CVE-2020-231281 PoCChamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new…
- CVE-2020-231602 PoCsRemote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary…
- CVE-2020-231612 PoCsLocal file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse…
- CVE-2020-231622 PoCsSensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to…
- CVE-2020-231711 PoCA vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip…
- CVE-2020-231721 PoCA vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due…
- CVE-2020-231781 PoCAn issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a…
- CVE-2020-231821 PoCThe component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to…
- CVE-2020-232081 PoCA stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2020-232091 PoCA stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2020-232141 PoCA stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2020-232171 PoCA stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2020-232571 PoCBuffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function…
- CVE-2020-232581 PoCAn issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in…
- CVE-2020-232591 PoCAn issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the…
- CVE-2020-232601 PoCAn issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the…
- CVE-2020-232661 PoCAn issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_code.c has a heap-based buffer overflow which can lead to a…
- CVE-2020-232671 PoCAn issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-based buffer…
- CVE-2020-232691 PoCAn issue was discovered in gpac 0.8.0. The stbl_GetSampleSize function in isomedia/stbl_read.c has a heap-based buffer overflow which can…
- CVE-2020-232731 PoCHeap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service…
- CVE-2020-232831 PoCInformation disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's…
- CVE-2020-233424 PoCsA CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
- CVE-2020-233621 PoCInsecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id…
- CVE-2020-233631 PoCCross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execute arbitrary code…
- CVE-2020-233691 PoCIn YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor…
- CVE-2020-233701 PoCIn YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote…
- CVE-2020-233711 PoCCross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows…
- CVE-2020-233731 PoCCross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary…
- CVE-2020-233741 PoCCross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject…
- CVE-2020-233761 PoCNoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be…
- CVE-2020-234381 PoCWondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.
- CVE-2020-234462 PoCsVerint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
- CVE-2020-234661 PoCCross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run…
- CVE-2020-234892 PoCsThe import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of…
- CVE-2020-234902 PoCsThere was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this…
- CVE-2020-235172 PoCsCross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject…
- CVE-2020-235181 PoCCross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which…
- CVE-2020-235223 PoCsPixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
- CVE-2020-235341 PoCA server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
- CVE-2020-235391 PoCAn issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval…
- CVE-2020-235651 PoCIrfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls…
- CVE-2020-235661 PoCIrfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.
- CVE-2020-235671 PoCIrfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer Divide By Zero…
- CVE-2020-235752 PoCsA directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow…
- CVE-2020-235801 PoCRemote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
- CVE-2020-235821 PoCA vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to…
- CVE-2020-235831 PoCOPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on…
- CVE-2020-235841 PoCUnauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands…
- CVE-2020-235851 PoCA remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware…
- CVE-2020-235861 PoCA vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated,…
- CVE-2020-235871 PoCA vulnerability found in the OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated,…
- CVE-2020-235881 PoCA vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote…
- CVE-2020-235891 PoCA vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote…
- CVE-2020-235901 PoCA vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote…
- CVE-2020-235911 PoCA vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary…
- CVE-2020-235921 PoCA vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote…
- CVE-2020-235931 PoCA vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote…
- CVE-2020-235951 PoCCross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive…
- CVE-2020-236301 PoCA blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
- CVE-2020-236431 PoCXSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
- CVE-2020-236441 PoCXSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
- CVE-2020-236481 PoCAsus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can…
- CVE-2020-236531 PoCAn insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and…
- CVE-2020-236861 PoCCross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified…
- CVE-2020-236891 PoCIn YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
- CVE-2020-236972 PoCsCross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
- CVE-2020-237051 PoCA global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of…
- CVE-2020-237061 PoCA heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through…
- CVE-2020-237071 PoCA heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through…
- CVE-2020-237151 PoCDirectory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
- CVE-2020-237211 PoCAn issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via…
- CVE-2020-237611 PoCCross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the…
- CVE-2020-237621 PoCCross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute…
- CVE-2020-237631 PoCSQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
- CVE-2020-237901 PoCAn Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
- CVE-2020-238142 PoCsMultiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2020-238241 PoCArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component…
- CVE-2020-238281 PoCA File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution…
- CVE-2020-238291 PoCinterface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote…
- CVE-2020-238301 PoCA Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote…
- CVE-2020-238311 PoCA Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0…
- CVE-2020-238321 PoCA Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows…
- CVE-2020-238331 PoCProjectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute…
- CVE-2020-238341 PoCInsecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to…
- CVE-2020-238351 PoCA Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0…
- CVE-2020-238361 PoCA Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10…
- CVE-2020-238371 PoCA Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin…
- CVE-2020-238392 PoCsA Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote…
- CVE-2020-238491 PoCStored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
- CVE-2020-238511 PoCA stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at…
- CVE-2020-238521 PoCA heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at…
- CVE-2020-238562 PoCsUse-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of…
- CVE-2020-238611 PoCA heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at…
- CVE-2020-238641 PoCAn issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file…
- CVE-2020-238722 PoCsA NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).
- CVE-2020-238732 PoCspdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump.
- CVE-2020-238742 PoCspdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.
- CVE-2020-238762 PoCspdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
- CVE-2020-238772 PoCspdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
- CVE-2020-238782 PoCspdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
- CVE-2020-238792 PoCspdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
- CVE-2020-239101 PoCStack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c.
- CVE-2020-239111 PoCAn issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in…
- CVE-2020-239121 PoCAn issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize()…
- CVE-2020-239141 PoCAn issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optimize() located in…
- CVE-2020-239151 PoCAn issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffer over-read.
- CVE-2020-239211 PoCAn issue was discovered in fast_ber through v0.4. yy::yylex() in asn_compiler.hpp has a heap-based buffer over-read.
- CVE-2020-239321 PoCAn issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It…
- CVE-2020-239342 PoCsAn issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the…
- CVE-2020-239352 PoCsKabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
- CVE-2020-239451 PoCA SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by…
- CVE-2020-239571 PoCPega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a…
- CVE-2020-239661 PoCSQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a…
- CVE-2020-239672 PoCsDr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT…
- CVE-2020-239681 PoCIlex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on…
- CVE-2020-239711 PoCgmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without…
- CVE-2020-239723 PoCsIn Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application…
- CVE-2020-239731 PoCKandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
- CVE-2020-239742 PoCsCreate-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social…
- CVE-2020-239752 PoCsWebexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.
- CVE-2020-239762 PoCsWebexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
- CVE-2020-239771 PoCKandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
- CVE-2020-239782 PoCsSQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
- CVE-2020-239791 PoC13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
- CVE-2020-239802 PoCsDesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
- CVE-2020-239811 PoC13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.
- CVE-2020-239822 PoCsDesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
- CVE-2020-239831 PoCMichael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
- CVE-2020-239841 PoCOnline Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
- CVE-2020-239891 PoCNeDi 1.9C allows pwsec.php oid XSS.
- CVE-2020-239921 PoCCross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET…