ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

6 results for “CVE-2020-1921”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-19217
Published
2022-05-06
CVSS:
8.8
ShadowTrackr CVSS:
5.2
Summary:
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
CVE:
CVE-2020-19216
Published
2022-05-06
CVSS:
8.8
ShadowTrackr CVSS:
5.2
Summary:
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
CVE:
CVE-2020-19215
Published
2022-05-06
CVSS:
8.8
ShadowTrackr CVSS:
5.2
Summary:
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
CVE:
CVE-2020-19213
Published
2022-05-06
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
CVE:
CVE-2020-19212
Published
2022-05-06
CVSS:
4.9
ShadowTrackr CVSS:
2.1
Summary:
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
CVE:
CVE-2020-1921
Published
2021-03-10
CVSS:
7.5
ShadowTrackr CVSS:
6.9
Summary:
In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.