Missing description

patch-1
Noam Rathaus 2021-03-24 08:50:31 +02:00
parent 93bc3a76b1
commit 904f156121
4 changed files with 4 additions and 0 deletions

View File

@ -4,6 +4,7 @@ info:
name: Mara CMS 7.5 - Reflective Cross-Site Scripting
author: pikpikcu
severity: medium
description: Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
reference: https://www.exploit-db.com/exploits/48777
tags: cve,cve2020,mara,xss

View File

@ -3,6 +3,7 @@ info:
name: NexusDB v4.50.22 Path Traversal
author: pikpikcu
severity: high
description: NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
reference: https://www.nexusdb.com/mantis/bug_view_advanced_page.php?bug_id=2371
tags: cve,cve2020,nexusdb,lfi

View File

@ -4,6 +4,7 @@ info:
name: DLINK DSL 2888a RCE
author: pikpikcu
severity: medium
description: An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
reference: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/d-link-multiple-security-vulnerabilities-leading-to-rce/
tags: cve,cve2020,dlink,rce

View File

@ -3,6 +3,7 @@ info:
name: IceWarp WebMail Reflected XSS
author: madrobot
severity: medium
description: IceWarp 11.4.5.0 allows XSS via the language parameter.
reference: https://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html
tags: cve,cve2020,xss,icewarp