Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2020-19217: SQL injection in admin/batch_manager.php · Issue #1012 · Piwigo/Piwigo

SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.

CVE
#sql#vulnerability#windows#php#auth#firefox
CVE-2022-27359

Foxit PDF Reader v11.2.1.53537 was discovered to contain a NULL pointer dereference via the component FoxitPDFReader.exe. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PHP file.

ZoneMinder Language Settings Remote Code Execution

This Metasploit module exploits an arbitrary file write in the debug log file option chained with a path traversal in the language settings that leads to remote code execution in ZoneMinder surveillance software versions before 1.36.13 and before 1.37.11

PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting

PHProjekt PhpSimplyGest and MyProjects version 1.3.0 suffer from a cross site scripting vulnerability.

CVE-2022-28079: College Management System In PHP With Source Code

College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.

CVE-2022-28530: Covid-19 Directory On Vaccination System 1.0 SQL Injection ≈ Packet Storm

Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.

CVE-2022-29940: Tags · LibreHealth / LibreHealth EHR / LibreHealth EHR Base · GitLab

In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.

CVE-2021-41739: Artica Proxy 4.30 cyrus.events.php RCE - rootless - Medium

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.