Show filters
373 Total Results
Displaying 161-170 of 373
Sort by:
Attacker Value
Unknown
CVE-2020-35151
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
0
Attacker Value
Unknown
CVE-2020-23834
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.
0
Attacker Value
Unknown
CVE-2020-14209
Disclosure Date: September 02, 2020 (last updated February 22, 2025)
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
0
Attacker Value
Unknown
CVE-2020-7713
Disclosure Date: September 01, 2020 (last updated February 22, 2025)
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
0
Attacker Value
Unknown
CVE-2020-13828
Disclosure Date: August 31, 2020 (last updated February 22, 2025)
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.
0
Attacker Value
Unknown
CVE-2020-14201
Disclosure Date: August 21, 2020 (last updated November 28, 2024)
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
0
Attacker Value
Unknown
CVE-2020-14475
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).
0
Attacker Value
Unknown
CVE-2020-14443
Disclosure Date: June 18, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2020-8321
Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-13240
Disclosure Date: May 20, 2020 (last updated February 21, 2025)
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
0