Show filters
119 Total Results
Displaying 101-110 of 119
Sort by:
Attacker Value
Unknown

CVE-2020-10426

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-groups.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10421

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-departments.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10419

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-categories.php by adding a question mark (?) followed by the payload.
Attacker Value
Unknown

CVE-2020-10481

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request.
Attacker Value
Unknown

CVE-2020-10466

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.
Attacker Value
Unknown

CVE-2020-10487

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
Attacker Value
Unknown

CVE-2020-10470

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.
Attacker Value
Unknown

CVE-2020-10493

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.
Attacker Value
Unknown

CVE-2020-10463

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
Reflected XSS in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.
Attacker Value
Unknown

CVE-2020-10492

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.