Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-4199

A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236289 was assigned to this vulnerability.

CVE
#sql#vulnerability#php
CVE-2023-38044: Joomla.org

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-34477: Online Virtual Classroom - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-34476: Proforms Basic - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-23758: Creative Gallery - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

CVE-2023-23757: BA Gallery - Joomla! Extension Directory

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Social-Commerce 3.1.6 Cross Site Scripting

Social-Commerce version 3.1.6 suffers from a cross site scripting vulnerability.

mooSocial 3.1.8 Cross Site Scripting

mooSocial version 3.1.8 suffers from a cross site scripting vulnerability.

Datalife Engine 10 SQL Injection

Datalife Engine version 10 suffers from a remote SQL injection vulnerability.

Cyber Infinite CMS 1.0 SQL Injection

Cyber Infinite CMS version 1.0 suffers from a remote SQL injection vulnerability.