Tag
#sql
Coupons CMS version 4.00 suffers from an open redirection vulnerability.
Given the privileged position these devices occupy on the networks they serve, they are prime targets for attackers, so their security posture is of paramount importance.
Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.
Joomla JLex Review extension version 6.0.1 suffers from a cross site scripting vulnerability.
Online Lab Diagnostic Management version 1.0 suffers from a remote SQL injection vulnerability.
CoolAdmin version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
City Variety LMS version 2.2 suffers from a cross site scripting vulnerability.
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
BMC Control-M Software v9.0.20.200 was discovered to contain a SQL injection vulnerability via the report-id parameter at /report/deleteReport.
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.