Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-32400: BugBounty/cve-2022-32400.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

CVE
#sql#vulnerability#php
CVE-2022-32396: BugBounty/cve-2022-32396.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4

CVE-2022-32391: BugBounty/cve-2022-32391.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

CVE-2022-32987: Simple Bakery Shop Management System in PHP MySQL

Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.

CVE-2022-34328: GitHub - jenaye/PMB

PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

CVE-2021-40956: SQL injection exists in the LaiKetui menu management function · Issue #13 · bettershop/LaikeTui

LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

CVE-2021-40954: Any file upload exists at the background plug-in · Issue #11 · bettershop/LaikeTui

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

CVE-2022-31361: Security Advisory: Docebo Community Edition <= 4.0.5 - Swascan

** UNSUPPORTED WHEN ASSIGNED ** Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2021-29055

Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.

Critical PHP Vulnerability Exposes QNAP NAS Devices to Remote Attacks

QNAP, Taiwanese maker of network-attached storage (NAS) devices, on Wednesday said it's in the process of fixing a critical three-year-old PHP vulnerability that could be abused to achieve remote code execution. "A vulnerability has been reported to affect PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24, and 7.3.x below 7.3.11 with improper nginx config," the hardware vendor said in an