Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2023-4199

A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236289 was assigned to this vulnerability.

CVE
#sql#vulnerability#php
Red Hat Security Advisory 2023-4494-01

Red Hat Security Advisory 2023-4494-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 102.14.0. Issues addressed include buffer overflow, bypass, and spoofing vulnerabilities.

Datalife Engine 10 SQL Injection

Datalife Engine version 10 suffers from a remote SQL injection vulnerability.

Database Compilation 1.2 Cross Site Scripting

Database Compilation CMS version 1.2 suffers from a cross site scripting vulnerability.

Cyber Infinite CMS 1.0 SQL Injection

Cyber Infinite CMS version 1.0 suffers from a remote SQL injection vulnerability.

Cvanav-DAW CMS 0.1 Cross Site Scripting

Cvanav-DAW CMS version 0.1 suffers from a cross site scripting vulnerability.

CSC-CMS 1.0.0 SQL Injection

CSC-CMS version 1.0.0 suffers from a remote SQL injection vulnerability.

CMS Genetics Centre 4.0.1 SQL Injection

CMS Genetics Centre version 4.0.1 suffers from a remote SQL injection vulnerability.

CMS BMGI International 4.0 Cross Site Scripting

CMS BMGI International version 4.0 suffers from a cross site scripting vulnerability.