Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2020-21486: PHPOK5.4 has sensitive information disclosure and sql injection · Issue #8 · qinggan/phpok

SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.

CVE
#sql#vulnerability#git#php
CVE-2020-20636

SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.

CVE-2020-20491: SQL Injection vulnerability found in fba extension · Issue #7612 · opencart/opencart

SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.

CVE-2020-20413: WUZHICMS-SQL-Injection/README.md at master · SuperSalsa20/WUZHICMS-SQL-Injection

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

NetArt Media PHP Hotel Site 2.0 Cross Site Scripting

NetArt Media PHP Hotel Site version 2.0 suffers from a cross site scripting vulnerability.

WordPress Kero jQuery/HTML Dashboard PRO 2.3.86 SQL Injection

WordPress Kero jQuery/HTML Dashboard PRO theme version 2.3.86 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

NetArt Media Blog LITE 2.1 Cross Site Scripting

NetArt Media Blog LITE version 2.1 suffers from a persistent cross site scripting vulnerability.

Student Study Center Management System 1.0 Cross Site Scripting

Student Study Center Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Jobpilot 2.61 SQL Injection

Jobpilot version 2.61 suffers from a remote SQL injection vulnerability.

Groomify 1.0 SQL Injection

Groomify version 1.0 suffers from a remote SQL injection vulnerability.