Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Adveris CMS 3.0 Cross Site Scripting

Adveris CMS version 3.0 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox
Anuranan SBAdmin 2.0 SQL Injection

Anuranan SBAdmin version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2023-26258: UDP Software | Unified Data Protection for On- and Off-Premises Workloads - Arcserve

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

Inout Search Engine AI Edition 1.1 Cross Site Scripting

Inout Search Engine AI Edition version 1.1 suffers from a cross site scripting vulnerability.

Vacation Rental 1.8 Cross Site Scripting

Vacation Rental version 1.8 suffers from a cross site scripting vulnerability.

Alumni Club Management Tools 2.2.7 SQL Injection / Arbitrary File Upload

Alumni Club Management Tools version 2.2.7 suffers from file upload and remote SQL injection vulnerabilities.

CVE-2021-4384: admin-page-galleries.php in photo-contest/tags/1.0.6/includes/admin – WordPress Plugin Repository

The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the load_images_thumbnail() and edit_gallery() functions. This makes it possible for unauthenticated attackers to edit galleries via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.