Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Allhandsmarketing CMS 3.01 SQL Injection

Allhandsmarketing CMS version 3.01 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
Car Rental Script 1.8 Cross Site Scripting

Car Rental Script version 1.8 suffers from a cross site scripting vulnerability.

Anuranan SBAdmin 2.0 SQL Injection

Anuranan SBAdmin version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2023-26258: UDP Software | Unified Data Protection for On- and Off-Premises Workloads - Arcserve

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

Inout Search Engine AI Edition 1.1 Cross Site Scripting

Inout Search Engine AI Edition version 1.1 suffers from a cross site scripting vulnerability.

Vacation Rental 1.8 Cross Site Scripting

Vacation Rental version 1.8 suffers from a cross site scripting vulnerability.