Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Coupons CMS 4.00 Open Redirection

Coupons CMS version 4.00 suffers from an open redirection vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox
ConverTo Video Downloader And Converter 1.4.2 File Download

ConverTo Video Downloader and Converter version 1.4.2 suffers from a file download vulnerability.

CVE-2023-38330: Security-Bulletins — OXID eSales Dokumentation

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.

CVE-2023-36121: OffSec’s Exploit Database Archive

Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.

CVE-2023-34869: Catering System (Only $59) | PHPJabbers

PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php?controller=pjAdmin&action=pjActionForgot.

CVE-2023-36118: Faculty Evaluation System - HackMD

Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.

Uvdesk 1.1.3 Shell Upload

Uvdesk version 1.1.3 suffers from a remote shell upload vulnerability.

CVE-2023-36211: OffSec’s Exploit Database Archive

The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel.

Online Diagnostic Lab Management 1.0 SQL Injection

Online Lab Diagnostic Management version 1.0 suffers from a remote SQL injection vulnerability.