Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2023-31946: BugReport/php/Online-Travel-Agency-System/bug8-File upload2.md at main · DiliLearngent/BugReport

File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.

CVE
#vulnerability#git#php
CVE-2023-31945: BugReport/php/Online-Travel-Agency-System/bug5-SQL-Injection-id.md at main · DiliLearngent/BugReport

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.

CVE-2023-31940: BugReport/php/Online-Travel-Agency-System/bug7-SQL-Injection-page_id.md at main · DiliLearngent/BugReport

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php.

CVE-2023-31939: BugReport/php/Online-Travel-Agency-System/bug4-SQL-Injection-costomer_id.md at main · DiliLearngent/BugReport

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.

CVE-2023-31943: BugReport/php/Online-Travel-Agency-System/bug6-SQL-Injection-ticket_id.md at main · DiliLearngent/BugReport

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php.

CVE-2023-31944: BugReport/php/Online-Travel-Agency-System/bug3-SQL-Injection-emp_id2.md at main · DiliLearngent/BugReport

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.

CVE-2023-31942: BugReport/php/Online-Travel-Agency-System/bug9-XSS-description.md at main · DiliLearngent/BugReport

Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php.

CVE-2023-31941: BugReport/php/Online-Travel-Agency-System/bug1-File upload.md at main · DiliLearngent/BugReport

File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.

CVE-2023-36106: 假诗人/PowerJob

An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.

CVE-2023-26469: GitHub - Orange-Cyberdefense/CVE-repository: Repository of CVE found by OCD people

In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.