Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2021-37782: Employee Record Management System in PHP and MySQL PHPGurukul

Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.

CVE
#sql#web#google#java#php#chrome
CVE-2021-38734: SEMCMS外贸网站商城系统 SCSHOP_v1.1 更新

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.

CVE-2021-35387: Hospital-Management-System/Hospital Management System.md at main · BigTiger2020/Hospital-Management-System

Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.

CVE-2021-35388: Hospital-Management-System/xss.md at main · BigTiger2020/Hospital-Management-System

Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.

High-Severity Flaws in Juniper Junos OS Affect Enterprise Networking Devices

Multiple high-severity security flaws have been disclosed as affecting Juniper Networks devices, some of which could be exploited to achieve code execution. Chief among them is a remote pre-authenticated PHP archive file deserialization vulnerability (CVE-2022-22241, CVSS score: 8.1) in the J-Web component of Junos OS, according to Octagon Networks researcher Paulos Yibelo. "This vulnerability

CVE-2022-43275: bug_report/RCE-1.md at main · 01001000entai/bug_report

Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-43276: bug_report/SQLi-1.md at main · 01001000entai/bug_report

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.

CVE-2022-3733: Web-Based Student Clearance System is vulnerable to a SQL Injection(edit-admin.php)_靳亚东的博客-CSDN博客

A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This affects an unknown part of the file Admin/edit-admin.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212415.

CVE-2022-3387

Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.