Missing description
parent
93bc3a76b1
commit
904f156121
|
@ -4,6 +4,7 @@ info:
|
|||
name: Mara CMS 7.5 - Reflective Cross-Site Scripting
|
||||
author: pikpikcu
|
||||
severity: medium
|
||||
description: Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
|
||||
reference: https://www.exploit-db.com/exploits/48777
|
||||
tags: cve,cve2020,mara,xss
|
||||
|
||||
|
|
|
@ -3,6 +3,7 @@ info:
|
|||
name: NexusDB v4.50.22 Path Traversal
|
||||
author: pikpikcu
|
||||
severity: high
|
||||
description: NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
|
||||
reference: https://www.nexusdb.com/mantis/bug_view_advanced_page.php?bug_id=2371
|
||||
tags: cve,cve2020,nexusdb,lfi
|
||||
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: DLINK DSL 2888a RCE
|
||||
author: pikpikcu
|
||||
severity: medium
|
||||
description: An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
|
||||
reference: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/
|
||||
tags: cve,cve2020,dlink,rce
|
||||
|
||||
|
|
|
@ -3,6 +3,7 @@ info:
|
|||
name: IceWarp WebMail Reflected XSS
|
||||
author: madrobot
|
||||
severity: medium
|
||||
description: IceWarp 11.4.5.0 allows XSS via the language parameter.
|
||||
reference: https://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html
|
||||
tags: cve,cve2020,xss,icewarp
|
||||
|
||||
|
|
Loading…
Reference in New Issue