Show filters
373 Total Results
Displaying 161-170 of 373
Sort by:
Attacker Value
Unknown

CVE-2020-35151

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
Attacker Value
Unknown

CVE-2020-23834

Disclosure Date: September 04, 2020 (last updated February 22, 2025)
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.
Attacker Value
Unknown

CVE-2020-14209

Disclosure Date: September 02, 2020 (last updated February 22, 2025)
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
Attacker Value
Unknown

CVE-2020-7713

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
Attacker Value
Unknown

CVE-2020-13828

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.
Attacker Value
Unknown

CVE-2020-14201

Disclosure Date: August 21, 2020 (last updated November 28, 2024)
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
Attacker Value
Unknown

CVE-2020-14475

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).
Attacker Value
Unknown

CVE-2020-14443

Disclosure Date: June 18, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
Attacker Value
Unknown

CVE-2020-8321

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2020-13240

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.