Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Adult Video Script 3.0 File Inclusion

Adult Video Script version 3.0 suffers from local and remote file inclusion vulnerabilities.

Packet Storm
#vulnerability#web#windows#google#php#auth#firefox
Adiscon LogAnalyzer 4.1.5 Cross Site Scripting

Adiscon LogAnalyzer version 4.1.5 suffers from a cross site scripting vulnerability.

PHPJabbers Knowledge Base Builder 3.0 Cross Site Scripting

PHPJabbers Knowledge Base Builder version 3.0 suffers from a cross site scripting vulnerability.

Adapt Inventory Management System 1.0.0 SQL Injection

Adapt Inventory Management System version 1.0.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2023-3303: ecard could sent if album is logged #1432 · Admidio/admidio@3d8bafa

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

CVE-2023-30260: Security advisory

Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.

CVE-2023-30258: Security advisory

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

CVE-2023-3383

A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affects an unknown part of the file /dipam/athlete-profile.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232239.

CVE-2023-3381: CVEReport/XSS2.md at main · M9KJ-TEAM/CVEReport

A vulnerability classified as problematic was found in SourceCodester Online School Fees System 1.0. Affected by this vulnerability is an unknown functionality of the file /paysystem/datatable.php of the component GET Parameter Handler. The manipulation of the argument doj leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-232237 was assigned to this vulnerability.