misc changes

patch-1
team-projectdiscovery 2021-01-02 10:26:15 +05:30
parent 7ed987a29e
commit 6cc3f88a5d
58 changed files with 58 additions and 58 deletions

View File

@ -1,4 +1,4 @@
id: cve-2020-0618
id: CVE-2020-0618
info:
name: RCE in SQL Server Reporting Services

View File

@ -1,4 +1,4 @@
id: cve-2020-10148
id: CVE-2020-10148
info:
name: SolarWinds Orion API Auth Bypass Leads to RCE (SUPERNOVA)

View File

@ -1,4 +1,4 @@
id: cve-2020-10199
id: CVE-2020-10199
info:
name: Nexus Repository Manager 3 RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-10204
id: CVE-2020-10204
info:
name: Sonatype Nexus Repository RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-11034
id: CVE-2020-11034
info:
name: GLPI v.9.4.6 - Open redirect

View File

@ -1,4 +1,4 @@
id: cve-2020-1147
id: CVE-2020-1147
info:
name: RCE at SharePoint Server (.NET Framework & Visual Studio) detection

View File

@ -1,4 +1,4 @@
id: cve-2020-11738
id: CVE-2020-11738
info:
name: WordPress Duplicator plugin Directory Traversal

View File

@ -1,4 +1,4 @@
id: cve-2020-12116
id: CVE-2020-12116
info:
name: Unauthenticated Zoho ManageEngine OpManger Arbitrary File Read

View File

@ -1,4 +1,4 @@
id: cve-2020-12720
id: CVE-2020-12720
info:
name: CVE-2020-12720 vBulletin SQLI

View File

@ -1,4 +1,4 @@
id: cve-2020-13167
id: CVE-2020-13167
info:
name: Netsweeper WebAdmin unixlogin.php Python Code Injection

View File

@ -1,4 +1,4 @@
id: cve-2020-13942
id: CVE-2020-13942
info:
name: Apache Unomi Remote Code Execution

View File

@ -1,4 +1,4 @@
id: cve-2020-14179
id: CVE-2020-14179
info:
name: Sensitive data exposure via insecure Jira endpoint

View File

@ -1,4 +1,4 @@
id: cve-2020-14181
id: CVE-2020-14181
info:
name: User enumeration via insecure Jira endpoint

View File

@ -1,4 +1,4 @@
id: cve-2020-14882
id: CVE-2020-14882
info:
name: Oracle WebLogic Server Unauthenticated RCE (and Patch Bypass)

View File

@ -1,4 +1,4 @@
id: cve-2020-15129
id: CVE-2020-15129
info:
name: Open-redirect in Traefik

View File

@ -1,4 +1,4 @@
id: cve-2020-15505
id: CVE-2020-15505
info:
name: RCE in MobileIron Core & Connector <= v10.6 & Sentry <= v9.8

View File

@ -1,4 +1,4 @@
id: cve-2020-15920
id: CVE-2020-15920
info:
name: Unauthenticated RCE at Mida eFramework on 'PDC/ajaxreq.php'

View File

@ -1,4 +1,4 @@
id: cve-2020-16139
id: CVE-2020-16139
info:
name: Cisco 7937G Denial-of-Service Reboot Attack

View File

@ -1,4 +1,4 @@
id: cve-2020-16846
id: CVE-2020-16846
info:
name: SaltStack Shell Injection

View File

@ -1,4 +1,4 @@
id: cve-2020-16952
id: CVE-2020-16952
info:
name: Microsoft SharePoint Server-Side Include (SSI) and ViewState RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-17505
id: CVE-2020-17505
info:
name: Artica Web Proxy 4.30 OS Command Injection

View File

@ -1,4 +1,4 @@
id: cve-2020-17506
id: CVE-2020-17506
info:
name: Artica Web Proxy 4.30 Authentication Bypass

View File

@ -1,4 +1,4 @@
id: cve-2020-2096
id: CVE-2020-2096
info:
name: Jenkins Gitlab Hook XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-2140
id: CVE-2020-2140
info:
author: j3ssie/geraldino2
name: Jenkin AuditTrailPlugin XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-23972
id: CVE-2020-23972
info:
name: Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload

View File

@ -1,4 +1,4 @@
id: cve-2020-24223
id: CVE-2020-24223
info:
name: Mara CMS 7.5 - Reflective Cross-Site Scripting

View File

@ -1,4 +1,4 @@
id: cve-2020-24312
id: CVE-2020-24312
info:
name: WordPress Plugin File Manager (wp-file-manager) Backup Disclosure

View File

@ -1,4 +1,4 @@
id: cve-2020-2551
id: CVE-2020-2551
info:
name: Unauthenticated Oracle WebLogic Server RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-25540
id: CVE-2020-25540
info:
name: ThinkAdmin 6 - Arbitrarily File Read (CVE-2020-25540)

View File

@ -1,4 +1,4 @@
id: cve-2020-26214
id: CVE-2020-26214
info:
name: Alerta Authentication Bypass (CVE-2020-26214)

View File

@ -1,4 +1,4 @@
id: cve-2020-3187
id: CVE-2020-3187
# Reference: https://twitter.com/aboul3la/status/1286809567989575685

View File

@ -1,4 +1,4 @@
id: cve-2020-3452
id: CVE-2020-3452
# Source: https://twitter.com/aboul3la/status/1286012324722155525

View File

@ -1,4 +1,4 @@
id: cve-2020-4463
id: CVE-2020-4463
info:
name: IBM Maximo Asset Management Information Disclosure via XXE

View File

@ -1,4 +1,4 @@
id: cve-2020-5284
id: CVE-2020-5284
info:
name: Next.js .next/ limited path traversal

View File

@ -1,4 +1,4 @@
id: cve-2020-5405
id: CVE-2020-5405
info:
name: Spring Cloud Directory Traversal

View File

@ -1,4 +1,4 @@
id: cve-2020-5410
id: CVE-2020-5410
info:
name: Directory Traversal in Spring Cloud Config Server

View File

@ -1,4 +1,4 @@
id: cve-2020-5412
id: CVE-2020-5412
info:
name: Full-read SSRF in Spring Cloud Netflix (Hystrix Dashboard)

View File

@ -1,4 +1,4 @@
id: cve-2020-5776
id: CVE-2020-5776
info:
name: Cross Site Request Forgery (CSRF) in MAGMI (Magento Mass Importer) Plugin

View File

@ -1,4 +1,4 @@
id: cve-2020-5777
id: CVE-2020-5777
info:
name: "Remote Auth Bypass in MAGMI (Magento Mass Importer) Plugin <= v0.7.23"

View File

@ -1,4 +1,4 @@
id: cve-2020-5902
id: CVE-2020-5902
info:
name: F5 BIG-IP TMUI RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-6287
id: CVE-2020-6287
info:
name: Create an Administrative User in SAP NetWeaver AS JAVA (LM Configuration Wizard)

View File

@ -1,4 +1,4 @@
id: cve-2020-7209
id: CVE-2020-7209
info:
name: LinuxKI Toolset 6.01 Remote Command Execution

View File

@ -1,4 +1,4 @@
id: cve-2020-7318
id: CVE-2020-7318
info:
name: McAfee ePolicy Orchestrator Reflected XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-7961
id: CVE-2020-7961
info:
name: Liferay Portal Unauthenticated RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-8091
id: CVE-2020-8091
info:
name: TYPO3 Cross-Site Scripting Vulnerability

View File

@ -1,4 +1,4 @@
id: cve-2020-8115
id: CVE-2020-8115
info:
name: Revive Adserver XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-8163
id: CVE-2020-8163
info:
name: Potential Remote Code Execution on Rails

View File

@ -1,4 +1,4 @@
id: cve-2020-8191
id: CVE-2020-8191
info:
name: Citrix ADC & NetScaler Gateway Reflected XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-8193
id: CVE-2020-8193
info:
name: Citrix unauthenticated LFI

View File

@ -1,4 +1,4 @@
id: cve-2020-8194
id: CVE-2020-8194
info:
name: Citrix ADC & NetScaler Gateway Reflected Code Injection

View File

@ -1,4 +1,4 @@
id: cve-2020-8209
id: CVE-2020-8209
info:
name: Citrix XenMobile Server Path Traversal

View File

@ -1,4 +1,4 @@
id: cve-2020-8512
id: CVE-2020-8512
info:
name: IceWarp WebMail XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-8982
id: CVE-2020-8982
info:
name: Citrix ShareFile StorageZones Unauthenticated Arbitrary File Read

View File

@ -1,4 +1,4 @@
id: cve-2020-9047
id: CVE-2020-9047
info:
name: exacqVision Web Service RCE

View File

@ -1,4 +1,4 @@
id: cve-2020-9344
id: CVE-2020-9344
info:
name: Jira Subversion ALM for enterprise XSS

View File

@ -1,4 +1,4 @@
id: cve-2020-9484
id: CVE-2020-9484
info:
name: Apache Tomcat RCE by deserialization

View File

@ -1,4 +1,4 @@
id: cve-2020-9496
id: CVE-2020-9496
info:
name: Apache OFBiz XML-RPC Java Deserialization

View File

@ -1,4 +1,4 @@
id: cve-2020-9757
id: CVE-2020-9757
info:
name: SEOmatic < 3.3.0 Server-Side Template Injection