Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Applebois

#19281of 53,630
13.8Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2020-15037
4.8
2020-10-07
Impresscms · Impresscms · CVE-2020-17551
**Name of the Vulnerable Software and Affected Versions** ImpressCMS version 1.4.0 **Description** The issue concerns a potential XSS in the modules/system/admin.php file, which could lead to arbitrary remote code execution. **Recommendations** For ImpressCMS version 1.4.0, consider restricting access to the vulnerable admin.php file in the modules/system directory until a patch is available.
PT-2020-12822
9
2020-07-13
Artica · Pandora Fms · CVE-2020-11749
**Name of the Vulnerable Software and Affected Versions** Pandora FMS versions 7.0 NG through 746 **Description** The issue concerns Multiple XSS vulnerabilities in different browser views of Pandora FMS. It can be triggered by a network administrator scanning a SNMP device, leading to Cross Site Scripting (XSS) that allows arbitrary code execution, potentially enabling Remote Code Execution as root or apache2. **Recommendations** For Pandora FMS versions 7.0 NG through 746, consider disabling the SNMP scanning feature until a patch is available to prevent potential exploitation of the XSS vulnerability. Restrict access to the browser views where the XSS vulnerability is present to minimize the risk of exploitation.