CVE-2020-22122
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.…
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.…
A vulnerability in the incconfig.php component of joyplus-cms v1.6 allows attackers to access sensitive information. Devamını Oku
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files. Devamını Oku
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files. Devamını Oku
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter. Devamını Oku
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php". Devamını Oku
In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege…
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with…
In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no…
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no…