mustgundogdu/Research

mustgundogdu/Research

Releases0
Stars8
Zero-day and Exploit code of some applications

CVE History

CVEPublishedCVSS v3CVSS v2

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2020-15178. Reason: This record is a duplicate of CVE-2020-15178. Notes: All CVE users should reference CVE-2020-15178 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

6.1 MEDIUM4.3 MEDIUM

Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

5.4 MEDIUM3.5 LOW

admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

9.8 CRITICAL10 HIGH

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

6.1 MEDIUM4.3 MEDIUM

The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.