Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-4543

A vulnerability was found in IBOS OA 4.5.5. It has been declared as critical. This vulnerability affects unknown code of the file ?r=recruit/contact/export&contactids=x. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238048. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE
#sql#vulnerability
CVE-2023-25848: The ArcGIS Server Map and Feature Service Security 2023 Update 1 Patch is now available

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

Debian Security Advisory 5482-1

Debian Linux Security Advisory 5482-1 - Edbo and Cedric Krier discovered that the Tryton application server does enforce record rules when only reading fields without an SQL type.

Business Directory Script 3.2 SQL Injection

Business Directory Script version 3.2 suffers from a remote SQL injection vulnerability.

Gravigra CMS 1.0 SQL Injection

Gravigra CMS version 1.0 suffers from a remote SQL injection vulnerability.

G And G Corporate CMS 1.0 SQL Injection

G and G Corporate CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Geeklog 2.1.0b1 SQL Injection

Geeklog version 2.1.0b1 suffers from a remote SQL injection vulnerability.

User Registration And Login And User Management System 3.0 SQL Injection

User Registration and Login and User Management System version 3.0 suffers from a remote SQL injection vulnerability.

CVE-2023-36317: Student Study Center Desk Management System using PHP (OOP) and MySQL DB Free Source Code

Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.