Security
Headlines
HeadlinesLatestCVEs

Tag

#firefox

TitanNit Web Control 2.01 / Atemio 7600 Code Injection

TitanNit Web Control 2.01 and Atemio 7600 suffer from a PHP code injection vulnerability.

Packet Storm
#vulnerability#web#windows#php#auth#firefox
Teacher Subject Allocation Management System 1.0 Insecure Settings

Teacher Subject Allocation Management System version 1.0 suffers from an ignored default credential vulnerability.

Task Management System 1.0 Code Injection

Task Management System version 1.0 suffers from a PHP code injection vulnerability.

Supply Chain Management 1.0 Backup Disclosure

Supply Chain Management version 1.0 suffers from a backup disclosure vulnerability.

Event Management System 1.0 Insecure Direct Object Reference

Event Management System version 1.0 suffers from an insecure direct object reference vulnerability.

Student Attendance Management System 1.0 Insecure Settings

Student Attendance Management System version 1.0 suffers from an ignored default credential vulnerability.

Printing Business Records Management System 1.0 Cross Site Request Forgery

Printing Business Records Management System version 1.0 suffers from a cross site request forgery vulnerability.

Online Eyewear Shop 1.0 Cross Site Request Forgery

Online Eyewear Shop version 1.0 suffers from a cross site request forgery vulnerability.

Nitro PDF Pro Local Privilege Escalation

The Nitro PDF Pro application uses a .msi installer file (embedded into an executable .exe installer file) for installation. The MSI installer uses custom actions in repair mode in an unsafe way. Attackers with low-privileged system access to a Windows system where Nitro PDF Pro is installed, can exploit the cached MSI installer's custom actions to effectively escalate privileges and get a command prompt running in context of NT AUTHORITY\SYSTEM. Versions prior to 14.26.1.0 and 13.70.8.82 and affected.

Student Study Center Management System 1.0 Insecure Settings

Student Study Center Management System version 1.0 suffers from an ignored default credential vulnerability.