Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Bang Resto 1.0 Cross Site Scripting

Bang Resto version 1.0 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#web#windows#apache#js#git#php#auth#firefox
GDidees CMS 3.9.1 Local File Disclosure / Directory Traversal

GDidees CMS version 3.9.1 suffers from file disclosure and directory traversal vulnerabilities.

CVE-2023-2017: Shopware 6 - Security Updates

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypass of CVE-2023-22731.

CVE-2023-2108

A vulnerability has been found in SourceCodester Judging Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_contestant.php. The manipulation of the argument contestant_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226147.

CVE-2021-36520: TrainSMART

A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.

CVE-2022-34128: Unauthenticated Remote Code Execution Due to Unrestricted File Upload

The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

CVE-2022-34127: Release GLPI ~10.0 : Version 4.0.2 disponible / available · InfotelGLPI/manageentities

The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.

CVE-2022-34126: Release GLPI ~10.0 : Version 3.1.1 disponible / available · InfotelGLPI/activity

The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.

CVE-2022-34125: Release GLPI ~10.0 : Version 3.0.3 disponible / available · InfotelGLPI/cmdb

front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.

CVE-2022-28353: MyBB External Redirect Warning 1.3 Cross Site Scripting ≈ Packet Storm

In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.