Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-26258: UDP Software | Unified Data Protection for On- and Off-Premises Workloads - Arcserve

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

CVE
#sql#web#mac#windows#microsoft#amazon#linux#oracle#vmware#aws#auth
Inout Search Engine AI Edition 1.1 Cross Site Scripting

Inout Search Engine AI Edition version 1.1 suffers from a cross site scripting vulnerability.

Vacation Rental 1.8 Cross Site Scripting

Vacation Rental version 1.8 suffers from a cross site scripting vulnerability.

Alumni Club Management Tools 2.2.7 SQL Injection / Arbitrary File Upload

Alumni Club Management Tools version 2.2.7 suffers from file upload and remote SQL injection vulnerabilities.

CVE-2021-4384: admin-page-galleries.php in photo-contest/tags/1.0.6/includes/admin – WordPress Plugin Repository

The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the load_images_thumbnail() and edit_gallery() functions. This makes it possible for unauthenticated attackers to edit galleries via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-3491: Limit "LIMIT" to numbers only + Disable upload theme (#1392) · FOSSBilling/FOSSBilling@2ddb743

Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-3490

SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.