Show filters
699 Total Results
Displaying 271-280 of 699
Sort by:
Attacker Value
Unknown

CVE-2020-25781

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
Attacker Value
Unknown

CVE-2020-25288

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitrary JavaScript.
Attacker Value
Unknown

CVE-2020-25735

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
Attacker Value
Unknown

CVE-2020-25734

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
webTareas through 2.1 allows files/Default/ Directory Listing.
Attacker Value
Unknown

CVE-2020-25733

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
Attacker Value
Unknown

CVE-2018-17145

Disclosure Date: September 10, 2020 (last updated February 22, 2025)
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Attacker Value
Unknown

CVE-2020-23660

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
Attacker Value
Unknown

CVE-2020-16266

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).
Attacker Value
Unknown

CVE-2020-14973

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.
Attacker Value
Unknown

CVE-2020-14930

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.