Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-28452: Better solutions for Small Laundry and Dry Cleaning Business

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVE
#sql#web#ios#android#mac#apple#google#git#java#php#sap#kotlin
Red Hat Security Advisory 2022-1436-01

Red Hat Security Advisory 2022-1436-01 - The OpenJDK 17 packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. This release of the Red Hat build of OpenJDK 17 for portable Linux serves as a replacement for the Red Hat build of OpenJDK 17 and includes security and bug fixes, and enhancements.

CVE-2022-29906: Administrative API module lets unauthenticated requests through

The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.

CVE-2022-29905: ⚓ T306741 FanBoxes: classic CSRF in Special:UserBoxes

The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.

GHSA-f6p5-76fp-m248: URL Rewrite vulnerability in multiple zendframework components

zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism. When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.

CVE-2022-28060: CVE/VictorCMS SQL.md at main · JiuBanSec/CVE

SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.

CVE-2022-28454: Limbas

Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-27860: Footer Text

Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.

Home Clean Service System 1.0 SQL Injection

Home Clean Service System version 1.0 suffers from a remote SQL injection vulnerability.

CVE-2022-28114: Arbitrary file deletion vulnerability · Issue #I4ZRMW · 德尚网络/DSCMS_open - Gitee.com

DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.