Tag
#php
This Metasploit module exploits an unauthenticated command injection vulnerability in Cacti versions through 1.2.22 in order to achieve unauthenticated remote code execution as the www-data user.
Inout Search Engine version 10.1.3 suffers from a cross site scripting vulnerability.
Inout Homestay version 2.0 suffers from a remote SQL injection vulnerability.
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.
IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.
A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.
The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_all_cache function in versions up to, and including, 3.0.12.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to clear the plugin's cache.
Ubuntu Security Notice 5818-1 - It was discovered that PHP incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code.
Inout RealEstate version 2.1.3 suffers from a remote SQL injection vulnerability.
Food Ordering System version 2 suffers from a remote shell upload vulnerability.