CVE-2020-21003: Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
Published Jun 3, 2021 · Updated Aug 4, 2024
Browse CVE records published in June 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 1976 matching CVEs · Page 13 of 40.
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
Published Jun 3, 2021 · Updated Aug 4, 2024
WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.
Published Jun 3, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.
Published Jun 21, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
Published Jun 28, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.
Published Jun 21, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.
Published Jun 28, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
Published Jun 21, 2021 · Updated Aug 4, 2024
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
Published Jun 23, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the user password.
Published Jun 21, 2021 · Updated Aug 4, 2024
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
Published Jun 16, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users of the current site.
Published Jun 21, 2021 · Updated Aug 4, 2024
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
Published Jun 23, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.
Published Jun 23, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.
Published Jun 21, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.
Published Jun 21, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.
Published Jun 21, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attackers can exploit the vulnerability to create a task.
Published Jun 21, 2021 · Updated Aug 4, 2024
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.
Published Jun 21, 2021 · Updated Aug 4, 2024
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
Published Jun 28, 2022 · Updated Aug 4, 2024
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
Published Jun 28, 2022 · Updated Aug 4, 2024
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
Published Jun 21, 2021 · Updated Aug 4, 2024
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It allows an authenticated WebGUI user with privileges to execute Stored Cross-site Scripting in the Captive Portal page.
Published Jun 17, 2021 · Updated Aug 4, 2024
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
Published Jun 22, 2021 · Updated Aug 4, 2024
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
Published Jun 29, 2021 · Updated Aug 4, 2024
Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.php?c=administrator&a=add".
Published Jun 22, 2021 · Updated Aug 4, 2024
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
Published Jun 23, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls.
Published Jun 24, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.
Published Jun 24, 2021 · Updated Aug 4, 2024
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
Published Jun 23, 2021 · Updated Aug 4, 2024
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.
Published Jun 24, 2021 · Updated Aug 4, 2024
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
Published Jun 22, 2021 · Updated Aug 4, 2024
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
Published Jun 23, 2021 · Updated Aug 4, 2024
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
Published Jun 18, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".
Published Jun 22, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.
Published Jun 24, 2021 · Updated Aug 4, 2024
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
Published Jun 7, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
Published Jun 23, 2021 · Updated Aug 4, 2024
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".
Published Jun 7, 2021 · Updated Aug 4, 2024
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
Published Jun 7, 2021 · Updated Aug 4, 2024
An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows attackers to transfer an arbitrary amount of tokens to an arbitrary address.
Published Jun 24, 2021 · Updated Aug 4, 2024
Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc8328952BA951AbE, an implementation for MillionCoin (MON).
Published Jun 24, 2021 · Updated Aug 4, 2024
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Published Jun 1, 2021 · Updated Aug 4, 2024
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
Published Jun 24, 2021 · Updated Aug 4, 2024
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.
Published Jun 9, 2021 · Updated Aug 4, 2024
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
Published Jun 28, 2020 · Updated Aug 4, 2024