Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-37152: GitHub - Fjowel/CVE-2022-37152: An SQL injection was discovered inOnline Diagnostic Lab Management System

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

CVE
#sql#vulnerability#git#php#auth
CVE-2021-40285: Security Issue: arbitrary file deletion vulnerability in “\system\admin\views\backup.html.php” · Issue #462 · danpros/htmly

htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

CVE-2022-36168: Wuzhicms v4.1.0 /coreframe/app/attachment/admin/index.php hava a directory traversal Vulnerability · Issue #202 · wuzhicms/wuzhicms

A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

CVE-2022-31798: Nortek Linear eMerge E3-Series Account Takeover ≈ Packet Storm

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-31499: Nortek Linear eMerge E3-Series Command Injection ≈ Packet Storm

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

CVE-2022-36696: vul-wiki/SQLi-7.md at master · k0xx11/vul-wiki

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.

CVE-2022-36695: vul-wiki/SQLi-8.md at master · k0xx11/vul-wiki

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.

CVE-2022-36716: bug_report/SQLi-10.md at main · k0xx11/bug_report

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php.

CVE-2022-36715: bug_report/SQLi-9.md at main · k0xx11/bug_report

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.

CVE-2022-36697: vul-wiki/SQLi-9.md at master · k0xx11/vul-wiki

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.