Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-48175: vulnfind/rce_ajax_request.md at main · y1s3m0/vulnfind

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

CVE
#sql#vulnerability#web#windows#apple#js#java#php#rce#auth#chrome#webkit
CVE-2022-48006: File upload vulnerability exists by modifying Upload.php configuration in backend. · Issue #35 · taogogo/taocms

An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.

CVE-2022-4395

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

CVE-2022-4680

The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

PHPJabbers Car Park Booking System 2.0 Cross Site Scripting

PHPJabbers Car Park Booking System version 2.0 suffers from a cross site scripting vulnerability.

PHPJabbers Event Ticketing System Script 1.0 Cross Site Scripting

PHPJabbers Event Ticketing System Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Travel Tours Script 1.0 SQL Injection

PHPJabbers Travel Tours Script version 1.0 suffers from a remote SQL injection vulnerability.

PHPJabbers Travel Tours Script 1.0 Cross Site Scripting

PHPJabbers Travel Tours Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Property Listing Script 3.1 SQL Injection

PHPJabbers Property Listing Script version 3.1 suffers from a remote SQL injection vulnerability.