Show filters
569 Total Results
Displaying 191-200 of 569
Sort by:
Attacker Value
Unknown

CVE-2020-35572

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
Attacker Value
Unknown

CVE-2020-23653

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.
Attacker Value
Unknown

CVE-2020-36190

Disclosure Date: January 12, 2021 (last updated February 22, 2025)
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms.
Attacker Value
Unknown

CVE-2020-26766

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.
Attacker Value
Unknown

CVE-2020-35132

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
Attacker Value
Unknown

CVE-2020-25967

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
Attacker Value
Unknown

CVE-2020-29315

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2020-21665

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
Attacker Value
Unknown

CVE-2020-21667

Disclosure Date: November 13, 2020 (last updated February 22, 2025)
In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
Attacker Value
Unknown

CVE-2020-22278

Disclosure Date: November 04, 2020 (last updated February 22, 2025)
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.