четвъртък, 23 септември 2021 г.

Weekly Update: a new vulnerability is published on the National Vulnerability Database (40 items)

New vulnerabilities from the NVD: CVE-2020-18735

A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18734

A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18731

A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18730

A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18778

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18776

In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18775

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18774

A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18773

An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18771

Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18917

The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Published at: August 24, 2021 at 11:15PM
View on website

August 25, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18913

EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.
Published at: August 24, 2021 at 11:15PM
View on website

August 25, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-10790

The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.
Published at: August 25, 2021 at 05:15PM
View on website

August 25, 2021 at 07:35PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18976

Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18974

Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18972

Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18971

Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19547

Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
Published at: August 25, 2021 at 11:15PM
View on website

August 26, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18065

Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
Published at: August 25, 2021 at 11:15PM
View on website

August 26, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19822

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19821

A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19709

Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19705

thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19704

A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19703

A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-14161

It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
Published at: August 26, 2021 at 02:15PM
View on website

August 26, 2021 at 03:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-14160

An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.
Published at: August 26, 2021 at 02:15PM
View on website

August 26, 2021 at 03:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18477

SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18476

SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18475

Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other users. When other users open the email, the malicious code will be executed.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18470

Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to rukovoditel_2.4.1/install/index.php.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18469

Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18468

Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18467

Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19000

Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
Published at: August 27, 2021 at 10:15PM
View on website

August 27, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18999

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
Published at: August 27, 2021 at 10:15PM
View on website

August 27, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18998

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
Published at: August 27, 2021 at 10:15PM
View on website

August 27, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18116

A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
Published at: August 28, 2021 at 12:15AM
View on website

August 28, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18114

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Published at: August 28, 2021 at 12:15AM
View on website

August 28, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18106

The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
Published at: August 27, 2021 at 11:15PM
View on website

August 28, 2021 at 01:33AM

via National Vulnerability Database


петък, 10 септември 2021 г.

Weekly Digest: New diabetes clinical trial (13 items)


New diabetes clinical trial: Prevention With the Health and Lifestyle Tool

Published on: August 16, 2021 at 07:00PM
Condition:   Type2 Diabetes
Intervention:   Behavioral: Lifestyle tool
Sponsor:   Region Skane
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05006508?term=diabetes&sfpd_d=14 August 16, 2021 at 07:22PM

via ClinicalTrials.gov


New diabetes clinical trial: mHealth Intervention to Support Diabetes Medication Adherence (Randomized Controlled Trial)

Published on: August 16, 2021 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Intervention:   Device: DIABE-TEXT
Sponsor:   Fundació d'investigació Sanitària de les Illes Balears
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05006872?term=diabetes&sfpd_d=14 August 16, 2021 at 07:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Learning Modality in Individuals With Diabetes Incompatible

Published on: August 16, 2021 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Intervention:   Behavioral: The Effect of Diabetes Education Based on Learning Modality
Sponsor:   Ege University
Active, not recruiting
https://clinicaltrials.gov/ct2/show/NCT05007197?term=diabetes&sfpd_d=14 August 16, 2021 at 07:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Puberty, Diabetes, and the Kidneys, When Eustress Becomes Distress (PANTHER Study)

Published on: August 17, 2021 at 07:00PM
Conditions:   Type 2 Diabetes Mellitus;   Diabetic Kidney Disease;   Adolescent Obesity;   Pre Diabetes;   Kidney Hypoxia;   Puberty
Interventions:   Drug: Aminohippurate Sodium Inj 20%;   Drug: Iohexol Inj 300 MG/ML;   Drug: Dextran 40
Sponsors:   University of Colorado Denver School of Medicine Barbara Davis Center;   National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK)
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05008276?term=diabetes&sfpd_d=14 August 17, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Effect of ZT-01 on Glucagon During Hypoglycemia in Type 1 Diabetes Mellitus

Published on: August 17, 2021 at 07:00PM
Conditions:   Type 1 Diabetes;   Hypoglycemia
Interventions:   Drug: ZT-01 low dose;   Drug: ZT-01 high dose;   Drug: Placebo
Sponsor:   Zucara Therapeutics Inc.
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05007977?term=diabetes&sfpd_d=14 August 17, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Well-child Visit Video Project

Published on: August 18, 2021 at 07:00PM
Condition:   Type 2 Diabetes
Interventions:   Behavioral: Educational Video about SCB;   Behavioral: Survey on child feeding and related knowledge and practices;   Behavioral: Educational Video other than SCB
Sponsor:   Emory University
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05011292?term=diabetes&sfpd_d=14 August 18, 2021 at 05:23PM

via ClinicalTrials.gov


New diabetes clinical trial: The Effect of 'Medical Nutrition Therapy' on Post-bariatric Hypoglycemia 2-4 Years After Gastric Bypass Surgery

Published on: August 18, 2021 at 07:00PM
Conditions:   Hypoglycemia;   Obesity, Morbid
Interventions:   Behavioral: Regular diet;   Behavioral: 10-point nutrition plan
Sponsors:   Central Norway Regional Health Authority;   Norwegian University of Science and Technology
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05011682?term=diabetes&sfpd_d=14 August 18, 2021 at 05:23PM

via ClinicalTrials.gov


New diabetes clinical trial: A Research Study to See How Well the New Weekly Medicine IcoSema, Which is a Combination of Insulin Icodec and Semaglutide, Controls Blood Sugar Level in People With Type 2 Diabetes Compared to Insulin Glargine Taken D...

Published on: August 19, 2021 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Interventions:   Drug: IcoSema;   Drug: Insulin glargine;   Drug: insulin aspart
Sponsor:   Novo Nordisk A/S
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05013229?term=diabetes&sfpd_d=14 August 19, 2021 at 06:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Using mHealth (Mobile Health) to Optimize Glycemic Control in Adults With Type 2 Diabetes: Proof of Concept Study

Published on: August 19, 2021 at 07:00PM
Condition:   Diabetes
Intervention:   Other: Intervention
Sponsors:   KU Leuven;   Jomo Kenyatta University of Agriculture and Technology
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05013294?term=diabetes&sfpd_d=14 August 19, 2021 at 06:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Characteristics of Young-onset Diabetes in Sub-Saharan Africa (YODA) Study

Published on: August 19, 2021 at 07:00PM
Conditions:   Type 1 Diabetes;   Diabetes, Autoimmune
Intervention:   Other: No intervention needed
Sponsors:   Yaounde Central Hospital;   University of Yaounde 1;   University of Exeter;   MRC/UVRI & LSHTM Uganda Research Unit
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05013346?term=diabetes&sfpd_d=14 August 19, 2021 at 06:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Application of Time Restriction Feeding in Patients With Type 2 Diabetes Mellitus

Published on: August 20, 2021 at 07:00PM
Condition:   Type 2 Diabetes
Intervention:   Behavioral: Time restricted feeding
Sponsors:   OhioHealth;   Ohio University
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05015504?term=diabetes&sfpd_d=14 August 20, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Efficacy and Safety of One-anastomosis Versus Roux-en-Y Gastric Bypass for Type 2 Diabetes Remission

Published on: August 20, 2021 at 07:00PM
Conditions:   Type2 Diabetes;   Complication of Bariatric Procedure
Interventions:   Procedure: The laparoscopic One-anastomosis gastric bypass will consist of:;   Procedure: The laparoscopic Roux-en-Y gastric bypass will consist of:
Sponsors:   Beijing Friendship Hospital;   Beijing Tiantan Hospital;   Shanghai Jiao Tong University Affiliated Sixth People's Hospital;   Shanghai Ninth People's Hospital Affiliated to Shanghai Jiao Tong University;   The Third Xiangya Hospital of Central South University;   The First Affiliated Hospital of Soochow University;   The Third People's Hospital of Chengdu;   Taipei Medical University Hospital
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05015283?term=diabetes&sfpd_d=14 August 20, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Digital Tools for Learning Diabetes: Combination of Animation and Gamification

Published on: August 20, 2021 at 07:00PM
Conditions:   Diabetes;   Educational Problems
Interventions:   Other: Traditional education;   Device: Diabetes Education supported by digital tools
Sponsor:   Saglik Bilimleri Universitesi
Completed
https://clinicaltrials.gov/ct2/show/NCT05015738?term=diabetes&sfpd_d=14 August 20, 2021 at 05:22PM

via ClinicalTrials.gov



Weekly Digest: a new vulnerability is published on the National Vulnerability Database (35 items)


New vulnerabilities from the NVD: CVE-2020-18705

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18704

Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18703

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18702

Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18701

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18699

Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18698

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
Published at: August 16, 2021 at 09:15PM
View on website

August 16, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-15955

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.
Published at: August 17, 2021 at 09:15PM
View on website

August 17, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18164

SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
Published at: August 17, 2021 at 11:15PM
View on website

August 18, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-13589

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or export function) is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
Published at: August 17, 2021 at 11:15PM
View on website

August 18, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-13588

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
Published at: August 17, 2021 at 11:15PM
View on website

August 18, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18746

SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
Published at: August 18, 2021 at 06:15PM
View on website

August 18, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-28146

Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
Published at: August 18, 2021 at 08:15PM
View on website

August 18, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-23069

Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
Published at: August 18, 2021 at 08:15PM
View on website

August 18, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18875

Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
Published at: August 18, 2021 at 08:15PM
View on website

August 18, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-22124

A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
Published at: August 18, 2021 at 09:15PM
View on website

August 18, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-22122

A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
Published at: August 18, 2021 at 09:15PM
View on website

August 18, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-22120

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.
Published at: August 18, 2021 at 09:15PM
View on website

August 18, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19669

Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
Published at: August 18, 2021 at 10:15PM
View on website

August 18, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-22345

/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.
Published at: August 19, 2021 at 12:15AM
View on website

August 19, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18748

Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.
Published at: August 19, 2021 at 07:15PM
View on website

August 19, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2013-1837

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Published at: August 19, 2021 at 07:15PM
View on website

August 19, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2013-1791

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2013. Notes: none.
Published at: August 19, 2021 at 07:15PM
View on website

August 19, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2013-0344

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2013. Notes: none.
Published at: August 19, 2021 at 07:15PM
View on website

August 19, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20645

Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
Published at: August 19, 2021 at 10:15PM
View on website

August 19, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20642

Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
Published at: August 19, 2021 at 10:15PM
View on website

August 19, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18900

A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128 allows attackers to execute arbitrary code.
Published at: August 20, 2021 at 01:15AM
View on website

August 20, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18899

An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
Published at: August 20, 2021 at 01:15AM
View on website

August 20, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18898

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
Published at: August 20, 2021 at 01:15AM
View on website

August 20, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18897

An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.
Published at: August 20, 2021 at 01:15AM
View on website

August 20, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18886

Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.
Published at: August 20, 2021 at 05:15PM
View on website

August 20, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18885

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
Published at: August 20, 2021 at 05:15PM
View on website

August 20, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18879

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
Published at: August 20, 2021 at 05:15PM
View on website

August 20, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18878

Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.
Published at: August 20, 2021 at 05:15PM
View on website

August 20, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18877

SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
Published at: August 20, 2021 at 05:15PM
View on website

August 20, 2021 at 07:33PM

via National Vulnerability Database