Tag
#windows
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
Learn how the latest ransomware variant has heightened attack execution speed and what that means for cybersecurity operations.
Symantec SiteMinder WebAgent version 12.52 suffers from a cross site scripting vulnerability.
WordPress Theme Medic theme version 1.0.0 suffers from having a weak password recovery mechanism for the forgot password flow.
WordPress Kero jQuery/HTML Dashboard PRO theme version 2.3.86 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Student Study Center Management System version 1.0 suffers from a persistent cross site scripting vulnerability.