Tag
#php
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
PHPJabbers Car Park Booking System version 2.0 suffers from a cross site scripting vulnerability.
Zstore version 6.6.0 suffers from a cross site scripting vulnerability.
PHPJabbers Event Ticketing System Script version 1.0 suffers from a cross site scripting vulnerability.
PHPJabbers Travel Tours Script version 1.0 suffers from a remote SQL injection vulnerability.
PHPJabbers Travel Tours Script version 1.0 suffers from a cross site scripting vulnerability.
PHPJabbers Property Listing Script version 3.1 suffers from a remote SQL injection vulnerability.