Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Sielco Analog FM Transmitter 2.12 'id' Cookie Brute Force Session Hijacking

The Cookie session ID 'id' is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication and manipulate the transmitter.

Zero Science Lab
#vulnerability#web#ios#git#php#auth
CVE-2023-27246: 2023-05-25-ziroudei/README.md at main · intruderlabs/2023-05-25-ziroudei

An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

CVE-2023-27008: [CVE-2023-27008] ATutor 2.2.1 Cross-Site Scripting via the Token Body Parameter

A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.

iBooking 1.0.8 Remote Shell Upload

iBooking version 1.0.8 suffers from a remote shell upload vulnerability.

Moodle LMS 4.0 Cross Site Scripting

Moodle LMS version 4.0 suffers from a cross site scripting vulnerability.

Apple Security Advisory 2023-03-27-5

Apple Security Advisory 2023-03-27-5 - macOS Big Sur 11.7.5 addresses bypass, code execution, integer overflow, out of bounds read, out of bounds write, and use-after-free vulnerabilities.

CVE-2023-27701: MuYucms sqldel.html has Arbitrary file deletion vulnerability · Issue #9 · MuYuCMS/MuYuCMS

MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.

CVE-2023-23330: Amano Xparc Local File Inclusion (CVE-2023–23330) - Saleh - Medium

amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.