Security Vulnerabilities
- CVEs Published In February 2020
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
ZPanel 10.0.1 has insufficient entropy for its password reset process.
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
D-Link DIR-100 4.03B07: cli.cgi CSRF
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
Joomla! core 1.7.1 allows information disclosure due to weak encryption
SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal information may be leaked to attackers via the vulnerability.
SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries and access arbitrary file in the database.