Tag
#php
ABB Cylon Aspect version 3.07.02 suffers from a vulnerability that allows an unauthenticated attacker to enable or disable the SSH daemon by sending a POST request to sshUpdate.php with a simple JSON payload. This can be exploited to start the SSH service on the remote host without proper authentication, potentially enabling unauthorized access or stop and deny service access.
TerraMaster TOS version 4.2.29 suffers from a remote code injection vulnerability leveraging a local file inclusion vulnerability.
SolarView Compact version 6.00 suffers from a PHP code injection vulnerability.
Openfire version 4.8.0 suffers from authentication bypass and code injection vulnerabilities.
MagnusBilling version 6.x suffers from a PHP code injection vulnerability.
Kafka UI version 0.7.1 suffers from a remote code injection vulnerability.
GL.iNet version 4.4.3 suffers from authentication bypass and code injection vulnerabilities.
Gibbon School Platform version 26.0.00 suffers from a PHP code injection vulnerability.
Craft CMS version 4.4.14 suffers from a PHP code injection vulnerability.
Chamilo version 1.11.18 suffers from a PHP code injection vulnerability.