Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

e2 Distr CMS 2.8.5.3 Backup Disclosure

e2 Distr CMS version 2.8.5.3 appears to leave backups in a world accessible directory under the document root.

Packet Storm
#vulnerability#windows#google#auth#firefox
DMIS:CRI LMS 2.0 SQL Injection

DMIS:CRI LMS version 2.0 suffers from a remote SQL injection vulnerability.

Discussion On Kontackt 1.18 Cross Site Scripting

Discussion On Kontackt The Exclusive PHP Social Network Platform version 1.18 suffers from a cross site scripting vulnerability.

Digisha CMS 1.2.7 SQL Injection

Digisha CMS version 1.2.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

DigaSell Digital Store PHP Script 1.0.0 SQL Injection

DigaSell Digital Store PHP Script version 1.0.0 suffers from a remote blind SQL injection vulnerability.

Doma CMS 1.0 Cross Site Scripting

Doma CMS version 1.0 suffers from a cross site scripting vulnerability.

Deprixa 3.2.5 Cross Site Request Forgery

Deprixa version 3.2.5 suffers from a cross site request forgery vulnerability.

EuroTel ETL3100 Transmitter Information Disclosure

The EuroTel ETL3100 TV and FM transmitters suffer from an unauthenticated configuration and log download vulnerability. This will enable the attacker to disclose sensitive information and help him in authentication bypass, privilege escalation and full system access.