ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

5 results for “CVE-2020-3539”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-3539
Published
2024-11-18
CVSS:
6.3
ShadowTrackr CVSS:
0.6
Summary:
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. The vulnerability is due to a failure to limit access to resources that are intended for users with Administrator privileges. An attacker could exploit this vulnerability by convincing a user to click a malicious URL. A successful exploit could allow a low-privileged attacker to list, view, create, edit, and delete templates in the same manner as a user with Administrator privileges.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVE:
CVE-2020-35398
Published
2021-12-23
CVSS:
5.3
ShadowTrackr CVSS:
1.7
Summary:
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
CVE:
CVE-2020-35391
Published
2021-01-01
CVSS:
9.6
ShadowTrackr CVSS:
7.7
Summary:
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.
CVE:
CVE-2020-35396
Published
2020-12-15
CVSS:
6.1
ShadowTrackr CVSS:
1.2
Summary:
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.
CVE:
CVE-2020-35395
Published
2020-12-15
CVSS:
6.1
ShadowTrackr CVSS:
0.5
Summary:
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field