Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2020
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-5084 pertains to instances of fwrite in Sphider Pro only, but do not exist in either Sphider or Sphider Plus.
CVSS Score
8.8
EPSS Score
0.067
Published
2020-02-10
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-02-10
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.
CVSS Score
9.8
EPSS Score
0.01
Published
2020-02-10
vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2020-02-10
Orange HRM 2.7.1 allows XSS via the vacancy name.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-02-10
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
CVSS Score
9.8
EPSS Score
0.004
Published
2020-02-10
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.
CVSS Score
8.8
EPSS Score
0.015
Published
2020-02-10
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-02-10
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-02-10
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
CVSS Score
5.4
EPSS Score
0.006
Published
2020-02-10


Contact Us

Shodan ® - All rights reserved