Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

eCommerce Marketplace Platform CMS 1.7 Cross Site Scripting

eCommerce Marketplace Platform CMS version 1.7 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#vulnerability#web#auth
CVE-2022-47769: Security Advisory: Serenissima Informatica – FastCheckIn (CVE-2022-47768/CVE-2022-47769/ CVE-2022-47770)

An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

CVE-2022-47770: Internet Speed Test

Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.

CVE-2023-24956: Forget Heart Message Box 1.1 has multiple SQL injections · Issue #1 · Mortalwangxin/lives

Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.

CVE-2022-45297: GitHub - tlfyyds/EQ

EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.

Hikvision Remote Code Execution / XSS / SQL Injection

Some Hikvision Hybrid SAN products were vulnerable to multiple remote code execution (command injection) vulnerabilities, including reflected cross site scripting, Ruby code injection, classic and blind SQL injection resulting in remote code execution that allows an adversary to execute arbitrary operating system commands and more. However, an adversary must be on the same network to leverage this vulnerability to execute arbitrary commands.

PHPJabbers Business Directory Script 3.2 Cross Site Scripting

PHPJabbers Business Directory Script version 3.2 suffers from a cross site scripting vulnerability.

PHPJabbers Auto Classifieds Script 3.2 Cross Site Scripting

PHPJabbers Auto Classifieds Script version 3.2 suffers from a cross site scripting vulnerability.

CVE-2023-24163: ExpressionUtil 表达式注入 · Issue #I6AJWJ · dromara/hutool - Gitee.com

SQL Inection vulnerability in Dromara hutool v5.8.11 allows attacker to execute arbitrary code via the aviator template engine.