ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

7 results for “CVE-2020-1926”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-19267
Published
2021-09-09
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE:
CVE-2020-19268
Published
2021-09-09
CVSS:
5.7
ShadowTrackr CVSS:
1.9
Summary:
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
CVE:
CVE-2020-19266
Published
2021-09-09
CVSS:
6.1
ShadowTrackr CVSS:
0.5
Summary:
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
CVE:
CVE-2020-19265
Published
2021-09-09
CVSS:
6.1
ShadowTrackr CVSS:
0.5
Summary:
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
CVE:
CVE-2020-19264
Published
2021-09-09
CVSS:
6.5
ShadowTrackr CVSS:
2.1
Summary:
A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.
CVE:
CVE-2020-19263
Published
2021-09-09
CVSS:
8.8
ShadowTrackr CVSS:
4.8
Summary:
A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/ApiAdminUser/itemEdit.
CVE:
CVE-2020-1926
Published
2021-03-16
CVSS:
5.9
ShadowTrackr CVSS:
4.6
Summary:
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8