Tag
#php
Simple Laboratory Management System version 1.0 suffers from a remote time-based SQL injection vulnerability.
Azon Dominator Affiliate Marketing Script suffers from a remote SQL injection vulnerability.
WordPress WPCode Lite plugin version 2.1.14 suffers from a persistent cross site scripting vulnerability.
Customer Support System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of cross site scripting in this version is attributed to Ahmed Abba in November of 2020.
In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
Automad version 2.0.0-alpha.4 suffers from a persistent cross site scripting vulnerability.
Poultry Farm Management System version 1.0 remote shell upload exploit. This is a variant of the original discovery of this flaw in this software version by Hejap Zairy in March of 2022.
Multiple content management system (CMS) platforms like WordPress, Magento, and OpenCart have been targeted by a new credit card web skimmer called Caesar Cipher Skimmer. A web skimmer refers to malware that is injected into e-commerce sites with the goal of stealing financial and payment information. According to Sucuri, the latest campaign entails making malicious modifications to the
Flatboard version 3.2 suffers from a persistent cross site scripting vulnerability.
Carbon Forum version 5.9.0 suffers from access control, cross site request forgery, file upload, outdated library, and remote SQL injection vulnerabilities.