Security
Headlines
HeadlinesLatestCVEs

Tag

#php

News Script Pro 2.4 Cross Site Scripting

News Script Pro version 2.4 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#vulnerability#web#php#auth#ssh
Funeral Script 3.1 Cross Site Scripting

Funeral Script version 3.1 suffers from a cross site scripting vulnerability.

FAQ Script 2.3 Cross Site Scripting

FAQ Script version 2.3 suffers from a cross site scripting vulnerability.

AMSS++ 2.0 Insecure Settings

AMSS++ version 2,0 appears to leave default credentials installed after installation.

Event Script 2.1 Cross Site Scripting

Event Script version 2.1 suffers from a cross site scripting vulnerability.

Classified Ads Script 1.8 Cross Site Scripting

Classified Ads Script version 1.8 suffers from a cross site scripting vulnerability.

GuestBook Script 2.2 Cross Site Scripting

GuestBook Script version 2.2 suffers from a cross site scripting vulnerability.

CVE-2023-1844: send-email.php in subscribe2/trunk/admin – WordPress Plugin Repository

The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.

CVE-2023-3427: Changeset 2931406 for salon-booking-system – WordPress Plugin Repository

The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on the 'save_customer' function. This makes it possible for unauthenticated attackers to change the admin role to customer or change the user meta to arbitrary values via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.