Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Cacti 1.2.22 Command Injection

This Metasploit module exploits an unauthenticated command injection vulnerability in Cacti versions through 1.2.22 in order to achieve unauthenticated remote code execution as the www-data user.

Packet Storm
#vulnerability#ubuntu#linux#apache#js#git#php#rce#auth#docker
Inout Search Engine 10.1.3 Cross Site Scripting

Inout Search Engine version 10.1.3 suffers from a cross site scripting vulnerability.

Inout Homestay 2.2 SQL Injection

Inout Homestay version 2.0 suffers from a remote SQL injection vulnerability.

CVE-2022-45639: Binary World - Informazioni,Sicurezza informatica,Sorgenti e tanto altro...

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.

CVE-2023-22630: IzyBat Orange casiers - SQLi injection

IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.

CVE-2022-46639: Ia Informática - Contatta con IA Informatica a Valencia.

A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.

CVE-2023-0447: Changeset 2844200 for youtube-channel – WordPress Plugin Repository

The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_all_cache function in versions up to, and including, 3.0.12.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to clear the plugin's cache.

Ubuntu Security Notice USN-5818-1

Ubuntu Security Notice 5818-1 - It was discovered that PHP incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code.

Inout RealEstate 2.1.3 SQL Injection

Inout RealEstate version 2.1.3 suffers from a remote SQL injection vulnerability.