Security
Headlines
HeadlinesLatestCVEs

Tag

#php

WiFi File Transfer 1.0.8 Cross Site Scripting

WiFi File Transfer version 1.0.8 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#web#android#google#redis#php#auth#wifi
MiniDVBLinux 5.4 Remote Root Command Injection

MiniDVBLinux version 5.4 suffers from an OS command injection vulnerability. This can be exploited to execute arbitrary commands with root privileges.

pfSense pfBlockerNG 2.1.4_26 Shell Upload

This Metasploit module leverages a remote shell upload vulnerability in pfSense pfBlockerNG plugin versions 2.1.4_26 and below. Note that version 3.x is unaffected.

MiniDVBLinux 5.4 Unauthenticated Stream Disclosure

MiniDVBLinux versions 5.4 and below suffer from an unauthenticated live stream disclosure when /tpl/tv_action.sh is called and generates a snapshot in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).

MiniDVBLinux 5.4 Change Root Password

MiniDVBLinux versions 5.4 and below root password changing proof of concept exploit.

CVE-2022-41472: 74cmsSE Storage cross site scripting vulnerability(XSS) · Issue #1 · xxhzz1/74cmsSE-Storage-cross-site-scripting-vulnerability

74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

CVE-2022-41498: bug_report/SQLi-1.md at main · aurigee/bug_report

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.

CVE-2022-42154: 74cmsSE Arbitrary file upload vulnerability · Issue #1 · xxhzz1/74cmsSE-Arbitrary-file-upload-vulnerability

An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-42237: sqlinj/poc at main · draco1725/sqlinj

A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.