Show filters
119 Total Results
Displaying 1-10 of 119
Sort by:
Attacker Value
Unknown

CVE-2020-11579

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.
Attacker Value
Unknown

CVE-2020-10400

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/article-collaboration.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10389

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings.
Attacker Value
Unknown

CVE-2020-10462

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
Reflected XSS in admin/edit-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.
Attacker Value
Unknown

CVE-2020-10498

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
Attacker Value
Unknown

CVE-2020-10434

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-versions.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10450

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-traffic.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10429

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-settings.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10415

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/index.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10394

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-glossary.php by adding a question mark (?) followed by the payload.