Security
Headlines
HeadlinesLatestCVEs

Tag

#php

GHSA-hm7p-r324-hhf3: phpseclib Infinite Loop vulnerability

Math/PrimeField.php in phpseclib through 2.0.41 has an infinite loop with composite primefields.

ghsa
#vulnerability#git#php
CVE-2023-27560: PrimeField: prevent infinite loop with composite primefields · phpseclib/phpseclib@6298d1c

Math/PrimeField.php in phpseclib through 2.0.41 has an infinite loop with composite primefields.

CVE-2023-1156

A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0. This vulnerability affects unknown code of the file admin/fecalysis_form.php. The manipulation of the argument itr_no leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222220.

CVE-2021-4328: 狮子鱼CMS ApiController.class.php SQL注入漏洞复现 - n00bk1ng的小窝

A vulnerability has been found in ???CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-222223.

CVE-2023-1151

A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the component Cookie Handler. The manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222163.

CVE-2023-1148: fixes #183 · flatpressblog/flatpress@3a32aad

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-1146: Stored XSS via blog author parameter on admin.php?p=config in flatpress

Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-1106: Unsanitized input returned in response is conducive to XSS exploitation in flatpress

Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-1131

A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222106 is the identifier assigned to this vulnerability.

CVE-2023-23315: [CVE-2023-23315] Improper neutralization of an SQL parameter in stripejs module for PrestaShop

The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.