Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2023-3393: Prevent twig from calling unsafe functions (#1337) · FOSSBilling/FOSSBilling@47343fb

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE
#git#php
CVE-2023-3391

A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file detailview.php. The manipulation of the argument employeeid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232288.

PHPJabbers Forum Script 3.0 Persistent Cross Site Scripting

PHPJabbers Forum Script version 3.0 suffers from a persistent cross site scripting vulnerability.

PHPJabbers Forum Script 3.0 Cross Site Scripting

PHPJabbers Forum Script version 3.0 suffers from a cross site scripting vulnerability.

PHPJabbers STIVA Blog Script 4.1 Cross Site Scripting

PHPJabbers STIVA Blog Script version 4.1 suffers from a cross site scripting vulnerability.

Adult Video Script 3.0 File Inclusion

Adult Video Script version 3.0 suffers from local and remote file inclusion vulnerabilities.

Adiscon LogAnalyzer 4.1.5 Cross Site Scripting

Adiscon LogAnalyzer version 4.1.5 suffers from a cross site scripting vulnerability.

PHPJabbers Knowledge Base Builder 3.0 Cross Site Scripting

PHPJabbers Knowledge Base Builder version 3.0 suffers from a cross site scripting vulnerability.

Adapt Inventory Management System 1.0.0 SQL Injection

Adapt Inventory Management System version 1.0.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.