ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

11 results for “CVE-2020-3707”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37079
Published
2026-02-06
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.
CVE:
CVE-2020-37078
Published
2026-02-03
CVSS:
7.2
ShadowTrackr CVSS:
5.1
Summary:
i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from the server's filesystem.
CVE:
CVE-2020-37077
Published
2026-02-03
CVSS:
6.9
ShadowTrackr CVSS:
4.6
Summary:
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.
CVE:
CVE-2020-37076
Published
2026-02-03
CVSS:
8.8
ShadowTrackr CVSS:
6.7
Summary:
Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.
CVE:
CVE-2020-37075
Published
2026-02-03
CVSS:
8.4
ShadowTrackr CVSS:
5.7
Summary:
LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute shellcode when importing computers from a file.
CVE:
CVE-2020-37073
Published
2026-02-03
CVSS:
8.6
ShadowTrackr CVSS:
6.1
Summary:
Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.
CVE:
CVE-2020-37074
Published
2026-02-03
CVSS:
8.4
ShadowTrackr CVSS:
5.7
Summary:
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer lists.
CVE:
CVE-2020-37071
Published
2026-02-03
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.
CVE:
CVE-2020-37072
Published
2026-02-03
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.
CVE:
CVE-2020-37070
Published
2026-02-03
CVSS:
8.6
ShadowTrackr CVSS:
6.1
Summary:
CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.
CVE:
CVE-2020-3707
Published
2021-12-20
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary: