Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-44411: Web Based Quiz System v1.0 is vulnerable to brute force attack

Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.

CVE
#sql#web#php#auth
CVE-2022-45039: WBCE CMS v1.5.4 getshell

An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-45036: WBCE CMS v1.5.4 is vulnerable to XSS via /search/index.php

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

CVE-2022-45040: WBCE CMS v1.5.4 is vulnerable to XSS via /admin/pages/sections_save.php

A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field.

CVE-2022-45038: WBCE CMS v1.5.4 is vulnerable to XSS via /admin/settings/save.php

A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.

CVE-2022-45037: WBCE CMS v1.5.4 is vulnerable to XSS via /admin/users/index.php

A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.

Helmet Store Showroom 1.0 SQL Injection

Helmet Store Showroom version 1.0 suffers from an authenticated remote SQL injection vulnerability.

Sanitization Management System 1.0 SQL Injection

Sanitization Management System version 1.0 suffers from a remote SQL injection vulnerability.

CVE-2022-4091

A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function query of the file food.php. The manipulation of the argument product_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214359.