Total
7187 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-19902 | 1 Wcms | 1 Wcms | 2024-11-21 | N/A | 9.8 CRITICAL |
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter. | |||||
CVE-2020-19877 | 1 Dbhcms Project | 1 Dbhcms | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information. | |||||
CVE-2020-19858 | 1 Plutinosoft | 1 Platinum | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy. | |||||
CVE-2020-19547 | 1 Popojicms | 1 Popojicms | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php. | |||||
CVE-2020-19360 | 1 Fhem | 1 Fhem | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure. | |||||
CVE-2020-19305 | 1 Metinfo | 1 Metinfo | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges. | |||||
CVE-2020-19304 | 1 Metinfo | 1 Metinfo | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information. | |||||
CVE-2020-19154 | 1 Jflyfox | 1 Jfinal Cms | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'. | |||||
CVE-2020-19150 | 1 Jflyfox | 1 Jfinal Cms | 2024-11-21 | 5.5 MEDIUM | 8.1 HIGH |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'. | |||||
CVE-2020-19147 | 1 Jflyfox | 1 Jfinal Cms | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'. | |||||
CVE-2020-19146 | 1 Jflyfox | 1 Jfinal Cms | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'. | |||||
CVE-2020-18878 | 1 Skycaiji | 1 Skycaiji | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'. | |||||
CVE-2020-18665 | 1 Webport | 1 Web Port | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings. | |||||
CVE-2020-18438 | 1 Phpok | 1 Phpok | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php. | |||||
CVE-2020-18191 | 1 Get-simple | 1 Getsimplecms | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php | |||||
CVE-2020-18190 | 1 Bludit | 1 Bludit | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture. | |||||
CVE-2020-18178 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax." | |||||
CVE-2020-18127 | 1 Indexhibit | 1 Indexhibit | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files. | |||||
CVE-2020-18070 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php". | |||||
CVE-2020-17564 | 1 Feifeicms | 1 Feifeicms | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component. |