Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Online Birth Certificate Management System 1.0 Cross Site Scripting

Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby
Online Birth Certificate Management System 1.0 Insecure Direct Object Reference

Online Birth Certificate Management System version 1.0 suffers from an insecure direct object reference vulnerability.

Online Birth Certificate Management System 1.0 Cross Site Request Forgery

Online Birth Certificate Management System version 1.0 suffers from a cross site request forgery vulnerability.

Food Ordering Management System 1.0 SQL Injection

Food Ordering Management System version 1.0 suffers from a remote SQL injection vulnerability.

CVE-2022-40099: Bug_report/SQLi-3.md at main · WYB-signal/Bug_report

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.

CVE-2022-40097: Bug_report/SQLi-1.md at main · WYB-signal/Bug_report

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.

CVE-2022-40098: Bug_report/SQLi-2.md at main · WYB-signal/Bug_report

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.

CVE-2022-30003: Online Market Place Site in PHP/OOP Free Source Code

Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.

Online Diagnostic Lab Management System 1.0 SQL Injection / Shell Upload

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

Gentoo Linux Security Advisory 202209-09

Gentoo Linux Security Advisory 202209-9 - Multiple vulnerabilities have been found in Smarty, the worst of which could result in remote code execution. Versions less than 4.2.1 are affected.