Security
Headlines
HeadlinesLatestCVEs

Tag

#php

HighPlus CMS 0.1.3 SQL Injection

HighPlus CMS version 0.1.3 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
Hospital HMS 2.7 SQL Injection

Hospital HMS version 2.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Hospital HMS 2 SQL Injection

Hospital HMS version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Hesk Rtl CMS 1 Cross Site Scripting

Hesk Rtl CMS version 1 suffers from a cross site scripting vulnerability.

haraj 1.1 Add Administrator

haraj version 1.1 suffers from an add administrator vulnerability.

HaasCMS 1.0 Cross Site Scripting

HaasCMS version 1.0 suffers from a cross site scripting vulnerability.

CVE-2023-39708: Free and Open Source inventory management system php source code

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.

CVE-2023-40752: Make An Offer Widget | PHPJabbers

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2023-40764: Car Rental Script | Car Rental System

User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.