Vulnerabilities > Chadhaajay
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-12 | CVE-2020-10394 | Cross-site Scripting vulnerability in Chadhaajay PHPkb 9.0 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-glossary.php by adding a question mark (?) followed by the payload. | 4.8 |
2020-03-12 | CVE-2020-10393 | Cross-site Scripting vulnerability in Chadhaajay PHPkb 9.0 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-field.php by adding a question mark (?) followed by the payload. | 4.8 |
2020-03-12 | CVE-2020-10392 | Cross-site Scripting vulnerability in Chadhaajay PHPkb 9.0 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-category.php by adding a question mark (?) followed by the payload. | 4.8 |
2020-03-12 | CVE-2020-10391 | Cross-site Scripting vulnerability in Chadhaajay PHPkb 9.0 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-article.php by adding a question mark (?) followed by the payload. | 4.8 |
2020-03-12 | CVE-2020-10390 | OS Command Injection vulnerability in Chadhaajay PHPkb 9.0 OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by saving the code to be executed as the wkhtmltopdf path via admin/save-settings.php. | 7.2 |
2020-03-12 | CVE-2020-10389 | Code Injection vulnerability in Chadhaajay PHPkb 9.0 admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings. | 7.2 |
2020-03-12 | CVE-2020-10388 | Cross-site Scripting vulnerability in Chadhaajay PHPkb 9.0 The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php (vulnerable file admin/include/functions-articles.php). | 5.4 |
2020-03-12 | CVE-2020-10387 | Path Traversal vulnerability in Chadhaajay PHPkb 9.0 Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file. | 4.9 |
2020-03-12 | CVE-2020-10386 | Unrestricted Upload of File with Dangerous Type vulnerability in Chadhaajay PHPkb 9.0 admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory. | 7.2 |