Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2022-30470: FileRun - Selfhosted File Manager with Sharing and Backup for Photos, Docs & More

In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

CVE
#sql#xss#csrf#vulnerability#web#android#mac#windows#apple#google#microsoft#apache#js#git#java#php#rce#perl#ldap#pdf#oauth#auth#docker#chrome#firefox
CVE-2022-30423: bug_report/RCE-1.md at main · ffYYy6x0y1/bug_report

Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.

CVE-2022-30817: bug_report/SQLi-1.md at main · k0xx11/bug_report

Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.

CVE-2022-30814: bug_report/SQLi-5.md at main · k0xx11/bug_report

elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.

CVE-2022-30810: bug_report/SQLi-2.md at main · k0xx11/bug_report

elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.

CVE-2022-30813: bug_report/SQLi-3.md at main · k0xx11/bug_report

elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.

CVE-2022-30809: bug_report/SQLi-1.md at main · k0xx11/bug_report

elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.

CVE-2022-31951: bug_report/SQLi-4.md at main · k0xx11/bug_report

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type.

CVE-2022-31948: bug_report/SQL-1.md at main · k0xx11/bug_report

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.