Tag
#php
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
Best POS Management System version 1.0 suffers from a remote shell upload vulnerability.
Best POS Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities.
Best POS Management System version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.
Demanzo Matrimony version 1.5 suffers from a cross site request forgery vulnerability.
Argon Dashboard version 1.1.2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
An issue in the urllib.parse component of Python before v3.11 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.