Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2020-13651

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java application. By providing an attacker-controlled URL, the client will obtain a rogue JNLP file specifying the installation of malicious JAR archives and executed with full privileges on the client computer.
Attacker Value
Unknown

CVE-2020-13977

Disclosure Date: June 09, 2020 (last updated February 21, 2025)
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.
Attacker Value
Unknown

CVE-2020-5295

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).
Attacker Value
Unknown

CVE-2020-10865

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity process.
Attacker Value
Unknown

CVE-2020-3794

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
Attacker Value
Unknown

CVE-2020-8128

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2013-3321

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
Attacker Value
Unknown

CVE-2013-4582

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.
Attacker Value
Unknown

CVE-2012-4919

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
Attacker Value
Unknown

CVE-2004-0285

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.