Security
Headlines
HeadlinesLatestCVEs

Tag

#php

GHSA-q2fp-jw87-86px: laravel-s vulnerable to Local File Inclusion

laravel-s prior to 3.7.36 is vulnerable to Local File Inclusion via `/src/Illuminate/Laravel.php`.

ghsa
#git#php
CVE-2023-33387: TÜV Rheinland – Aufgedeckte Schwachstellen

A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.

CVE-2023-29931: Local File Inclusion (LFI) vulnerability · Issue #437 · hhxsv5/laravel-s

laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.

GHSA-47p7-xfcc-4pv9: php-imap vulnerable to RCE through a directory traversal vulnerability

### Summary An unsanitized attachment filename allows any unauthenticated user to leverage a directory traversal vulnerability which results in a remote code execution vulnerability. ### Details An attacker can send an email with a malicious attachment to the inbox, which gets crawled with webklex/php-imap or webklex/laravel-imap. Prerequisite for the vulnerability is that the script stores the attachments without providing a `$filename`, or providing an unsanitized `$filename`, in `src/Attachment::save(string $path, string $filename = null)` (https://github.com/Webklex/php-imap/blob/5.2.0/src/Attachment.php#L251-L255). In this case, where no `$filename` gets passed into the `Attachment::save()` method, the package would use a series of unsanitized and insecure input values from the mail as fallback (https://github.com/Webklex/php-imap/blob/5.2.0/src/Attachment.php#L252). Even if a developer passes a `$filename` into the `Attachment::save()` method, e.g. by passing the name or filenam...

CVE-2023-33591: CVE/CVE 2023-33591 at main · DARSHANAGUPTA10/CVE

User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.

PHP Online School 1.0 Cross Site Scripting

PHP Online School version 1.0 suffers from a cross site scripting vulnerability.

PHP Mall 5.0 Cross Site Scripting

PHP Mail version 5.0 suffers from a cross site scripting vulnerability.

WordPress Super Socializer 7.13.52 Cross Site Scripting

WordPress Super Socializer plugin version 7.13.52 suffers from a cross site scripting vulnerability.

Accent Microcomputers CMS 2.4 Directory Traversal

Accent Microcomputers CMS version 2.4 suffers from a directory traversal vulnerability.

PHP Car Dealer 3.0 Cross Site Scripting

PHP Car Dealer version 3.0 suffers from a cross site scripting vulnerability.