Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-29624: Arbitrary file upload vulnerability exists in tpcms v3.2 · Issue #I533KY · 快乐源泉/tpcms - Gitee.com

An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.

CVE
#vulnerability#web#git#php
CVE-2022-31973: bug_report/delet-file-1.md at main · k0xx11/bug_report

Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img.

CVE-2022-31971: bug_report/SQLi-3.md at main · k0xx11/bug_report

ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/view_response&id=.

CVE-2022-31977: bug_report/SQLi-3.md at main · k0xx11/bug_report

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVE-2022-31976: bug_report/SQLi-4.md at main · k0xx11/bug_report

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.

CVE-2022-31970: bug_report/SQLi-4.md at main · k0xx11/bug_report

ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/manage_response&id=.

CVE-2022-31978: bug_report/SQLi-5.md at main · k0xx11/bug_report

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.

CVE-2022-31975: bug_report/SQLi-2.md at main · k0xx11/bug_report

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.

CVE-2019-12349: zzcms 2019 admin/dl_sendsms.php SQL injection · Issue #2 · cby234/zzcms

An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.

CVE-2019-12350: zzcms 2019 dl/dl_download.php SQL injection · Issue #4 · cby234/zzcms

An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.