Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-25848: The ArcGIS Server Map and Feature Service Security 2023 Update 1 Patch is now available

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

CVE
#sql#vulnerability#web#auth
Debian Security Advisory 5482-1

Debian Linux Security Advisory 5482-1 - Edbo and Cedric Krier discovered that the Tryton application server does enforce record rules when only reading fields without an SQL type.

Business Directory Script 3.2 SQL Injection

Business Directory Script version 3.2 suffers from a remote SQL injection vulnerability.

Gravigra CMS 1.0 SQL Injection

Gravigra CMS version 1.0 suffers from a remote SQL injection vulnerability.

G And G Corporate CMS 1.0 SQL Injection

G and G Corporate CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Geeklog 2.1.0b1 SQL Injection

Geeklog version 2.1.0b1 suffers from a remote SQL injection vulnerability.

User Registration And Login And User Management System 3.0 SQL Injection

User Registration and Login and User Management System version 3.0 suffers from a remote SQL injection vulnerability.

CVE-2023-36317: Student Study Center Desk Management System using PHP (OOP) and MySQL DB Free Source Code

Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.

SugarCRM 12.2.0 SQL Injection

SugarCRM versions 12.2.0 and below suffer from multiple remote SQL injection vulnerabilities.