Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2020-18409: Bug: CatfishCMS V 4.8.63 CSRF · Issue #5 · xwlrbh/Catfish

Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html.

CVE
#csrf#vulnerability#git#php
CVE-2020-18414: Bug: ChaojiCMS V2.18 XSS #3 · Issue #3 · GodEpic/chaojicms

Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via /index.php?admin-master-webset.

CVE-2020-19902: BUG:A Arbitrary File Reading Vulnerability in wex/cssjs.php · Issue #3 · vedees/wcms

Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

CVE-2020-18416: Bug: Jymusic V2.0.0 CSRF · Issue #1 · dtorp06/jymusic

An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.

CVE-2020-18410: Bug: ChaojiCMS V2.18 XSS #6 · Issue #6 · GodEpic/chaojicms

A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges.

CVE-2020-18413: Bug: ChaojiCMS V2.18 XSS #5 · Issue #5 · GodEpic/chaojicms

Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code.

CVE-2020-18418: Vulnerability-detection/feifeicms/FeiFeiCMS_4.1_csrf.doc at master · GodEpic/Vulnerability-detection

A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.

MyBB Favicon 1.0 Cross Site Scripting

MyBB Favicon plugin version 1.0 suffers from a cross site scripting vulnerability.

Job Board 1.0 Shell Upload

Job Board version 1.0 suffers from a remote shell upload vulnerability.

PrestaShop Winbiz Payment Improper Limitation

PrestaShop Winbiz Payment module suffers from an improper limitation of a Pathname to a restricted directory.