Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CRM Education Akademik 9.0 Directory Traversal

CRM Education Akademik version 9.0 suffers from a directory traversal vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox
CREDITS PREVICINI CMS 1.02 Cross Site Scripting

CREDITS PREVICINI CMS version 1.02 suffers from a cross site scripting vulnerability.

Creative Commons Attribution 3.0 SQL Injection

Creative Commons Attribution version 3.0 suffers from a remote SQL injection vulnerability.

Courier Deprixa Pro Integrated Web System 3.2.5 Cross Site Request Forgery

Courier Deprixa Pro Integrated Web System version 3.2.5 suffers from a cross site request forgery vulnerability.

ConverTo Video Downloader And Converter 1.4.2 File Download

ConverTo Video Downloader and Converter version 1.4.2 suffers from a file download vulnerability.

CVE-2023-38330: Security-Bulletins — OXID eSales Dokumentation

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.

CVE-2023-36121: OffSec’s Exploit Database Archive

Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.

CVE-2023-34869: Catering System (Only $59) | PHPJabbers

PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php?controller=pjAdmin&action=pjActionForgot.

CVE-2023-36118: Faculty Evaluation System - HackMD

Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.