Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-43980: [CVE-2023-43980] Improper neutralization of SQL parameter in Presto Changeo - Test Site Creator module for PrestaShop

Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

CVE
#sql#vulnerability#web#js#php#perl#auth
CVE-2023-43893: CVE/netis_N3/blind command injection in wake on lan functionality in wakeup_mac parameter.md at main · adhikara13/CVE

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

CVE-2023-43892: CVE/netis_N3/blind command injection in hostname parameter in wan settings.md at main · adhikara13/CVE

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.

CVE-2023-43891: CVE/netis_N3/command injection in changing password feature.md at main · adhikara13/CVE

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

CVE-2023-44011: Vulnerability-Disclosures/2023/CVE-2023-44011 at main · Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures

An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

CVE-2023-44012: Vulnerability-Disclosures/2023/CVE-2023-44012 at main · Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures

Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.

CVE-2023-43267: CVE-2023-43267

A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.

CVE-2023-43361: GitHub - xiph/vorbis-tools: Command-line tools for creating and playing Ogg Vorbis files.

Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.

CVE-2023-43268: GitHub - Fliggyaaa/DeYue-remote-vehicle-management-system

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

CVE-2023-44008: Vulnerability-Disclosures/2023/CVE-2023-44008 at main · Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.