Tag
#php
Courier Management System version 1.0 suffers from a cross site request forgery vulnerability.
Company Visitor Management version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
CMSsite version 1.0 suffers from a remote shell upload vulnerability.
CMS RIMI version 1.3 suffers from cross site request forgery and arbitrary file upload vulnerabilities.
Client Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
CCMS Project version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Biobook Social Networking Site version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
This Metasploit module exploits a remote code execution vulnerability in SPIP versions up to and including 4.2.12. The vulnerability occurs in SPIP's templating system where it incorrectly handles user-supplied input, allowing an attacker to inject and execute arbitrary PHP code. This can be achieved by crafting a payload manipulating the templating data processed by the echappe_retour() function, invoking traitements_previsu_php_modeles_eval(), which contains an eval() call.
AVMS Project version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Online Survey System version 1.0 suffers from a cross site request forgery vulnerability.