Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown

CVE-2020-29228

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
Attacker Value
Unknown

CVE-2020-29231

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.
Attacker Value
Unknown

CVE-2020-29230

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.
Attacker Value
Unknown

CVE-2020-29472

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
Attacker Value
Unknown

CVE-2020-29474

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
Attacker Value
Unknown

CVE-2020-35252

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
Attacker Value
Unknown

CVE-2020-35276

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Attacker Value
Unknown

CVE-2020-35273

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.
Attacker Value
Unknown

CVE-2020-35395

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
Attacker Value
Unknown

CVE-2020-35396

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.