Security
Headlines
HeadlinesLatestCVEs

Tag

#php

NanoCMS 0.4 Remote Code Execution

NanoCMS version 0.4 suffers from an authenticated remote code execution vulnerability.

Packet Storm
#vulnerability#web#linux#git#php#rce#auth#firefox
CuteEditor For PHP 6.6 Directory Traversal

CuteEditor For PHP version 6.6 suffers from a directory traversal vulnerability.

WordPress Duplicator 1.4.6 Backup Disclosure

WordPress Duplicator plugin versions 1.4.6 and below suffer from a backup disclosure vulnerability.

WordPress Duplicator 1.4.7 Information Disclosure

WordPress Duplicator plugin versions 1.4.7 and below suffer from an information disclosure vulnerability.

CodeIgniter CMS 4.2.0 SQL Injection

CodeIgniter CMS version 4.2.0 suffers from a remote SQL injection vulnerability.

WordPress SeatReg 1.23.0 Open Redirect

WordPress SeatReg plugin version 1.23.0 suffers from an open redirection vulnerability.

Crime Reporting System 1.0 SQL Injection

Crime Reporting System version 1.0 suffers from a remote SQL injection vulnerability.

CVE-2022-1585

The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.

CVE-2022-1600

The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

CVE-2022-26308: Coordinated CVEs

Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.