Security
Headlines
HeadlinesLatestCVEs

Tag

#firefox

MVC Shop 0.5 Directory Traversal

MVC Shop version 0.5 suffers from a directory traversal vulnerability.

Packet Storm
#vulnerability#web#windows#google#git#php#auth#firefox
PHP Live 3.1 Cross Site Scripting

PHP Live version 3.1 suffers from a cross site scripting vulnerability.

Acelle Email Marketing 4.0.25 Arbitrary File Upload

Acelle Email Marketing version 4.0.25 suffers from an arbitrary file upload vulnerability.

Kesion CMS X 2.0 Add Administrator

Kesion CMS X version 2.0 suffers from an unauthenticated add administrator vulnerability.

CVE-2023-0342: Ops Manager Server Changelog — MongoDB Ops Manager 6.0

MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not include the PEM files themselves. This issue affects MongoDB Ops Manager v5.0 prior to 5.0.21 and MongoDB Ops Manager v6.0 prior to 6.0.12

CVE-2023-0708: Changeset 2907471 – WordPress Plugin Repository

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a a page containing the shortcode when the submission id is present in the query string. Note that getting the JavaScript to execute requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database.

Debian Security Advisory 5421-1

Debian Linux Security Advisory 5421-1 - Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

MVC Shop 0.5 Cross Site Scripting

MVC Shop version 0.5 suffers from a cross site scripting vulnerability.

NETXPERTS CMS 0.1 SQL Injection

NETXPERTS CMS version 0.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Anuranan SBAdmin 2 Insecure Settings

Anuranan SBAdmin version 2 appears to leave default credentials installed after installation.