[FD] [AIT-SA-20210215-04] CVE-2020-24036: ForkCMS PHP Object Injection

2021-03-12 Thread sec-advisory
ForkCMS PHP Object Injection = | Identifier: | AIT-SA-20210215-04 | | Target: | ForkCMS | | Vendor: | ForkCMS | | Version: | all versions below version 5.8.3 | | CVE: | CVE-2020-24036 | | Accessibility: | Remote | | Severity: | Medium | | Author: | Wolfgang Hotwagner (AIT

[FD] [AIT-SA-20210215-03] CVE-2020-24912: QCube Cross-Site-Scripting

2021-03-12 Thread sec-advisory
QCube Cross-Site-Scripting == | Identifier: | AIT-SA-20210215-03 | | Target: | QCubed Framework | | Vendor: | QCubed | | Version: | all versions including 3.1.1 | | CVE: | CVE-2020-24912 | | Accessibility: | Remote | | Severity: | High | | Author: | Wolfgang Hotwagner (AIT

[FD] [AIT-SA-20210215-02] CVE-2020-24913: QCubed SQL Injection

2021-03-12 Thread sec-advisory
QCubed SQL Injection == | Identifier: | AIT-SA-20210215-02 | | Target: | QCubed Framework | | Vendor: | QCubed | | Version: | all versions including 3.1.1 | | CVE: | CVE-2020-24913 | | Accessibility: | Remote | | Severity: | Critical | | Author: | Wolfgang Hotwagner (AIT Austrian

[FD] [AIT-SA-20210215-01] CVE-2020-24914: QCubed PHP Object Injection

2021-03-12 Thread sec-advisory
QCubed PHP Object Injection === | Identifier: | AIT-SA-20210215-01 | | Target: | QCubed Framework | | Vendor: | QCubed | | Version: | all versions including 3.1.1 | | CVE: | CVE-2020-24914 | | Accessibility: | Remote | | Severity: | Critical | | Author: | Wolfgang