Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2022-28799: Report security vulnerabilities | TikTok Help Center

The TikTok application before 23.8.4 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.

CVE
#sql#xss#csrf#vulnerability#web#android#java#perl#ssrf#auth
CVE-2022-30513: School Dormitory Management System in PHP/OOP Free Source Code

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

CVE-2022-30496: SQL Injection no IDCE MV

SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.

CVE-2022-30797: bug_report/SQLi-3.md at main · k0xx11/bug_report

Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.

CVE-2022-30795: bug_report/SQLi-4.md at main · k0xx11/bug_report

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.

CVE-2022-30798: bug_report/SQLi-2.md at main · k0xx11/bug_report

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.

CVE-2022-30794: bug_report/SQLi-1.md at main · k0xx11/bug_report

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.

CVE-2022-30799: bug_report/SQLi-5.md at main · k0xx11/bug_report

Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.

CVE-2022-29627: OpenSource/exploit_idor.md at main · nsparker1337/OpenSource

An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.

CVE-2022-29628: OpenSource/exploit_rxss.md at main · nsparker1337/OpenSource

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.