Tag
#firefox
Event Locations CMS version 1.0.1 suffers from a remote shell upload vulnerability.
DoorGets CMS version 7.0 suffers from an information leakage vulnerability.
Emaar Real Estate Agency Directory System version 5.7 suffers from a remote shell upload vulnerability.
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.
ExcessWeb and Network CMS version 4.0 suffers from a database disclosure vulnerability.
Evsanati Radyo version 1.0 suffers from an ignored default credential vulnerability.
Event Locations CMS version 1.0.1 suffers from a cross site scripting vulnerability.
Erim Upload version 4 suffers from a database disclosure vulnerability.