Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

The Shop 2.5 SQL Injection

The Shop version 2.5 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#vulnerability#web#windows#apple#linux#js#auth#chrome#webkit
BBoard Forum 1.0 Cross Site Scripting

BBoard Forum version 1.0 suffers from a persistent cross site scripting vulnerability.

WG Ticket 1.0 Cross Site Scripting

WG Ticket version 1.0 suffers from a cross site scripting vulnerability.

Coursela Personal Course Selling Website 1.0 Cross Site Scripting

Coursela Personal Course Selling Website version 1.0 suffers from a cross site scripting vulnerability.

Coursemat Multi-Tenant Course Selling Website 1.1 Cross Site Scripting

Coursemat Multi-Tenant Course Selling Website version 1.1 suffers from a cross site scripting vulnerability.

elearning-SES 1.0 Sql Injection

elearning-SES version 1.0 suffers from a remote SQL injection vulnerability.

RentEquip Multipurpose Rental 1.0 Cross Site Scripting

RentEquip Multipurpose Rental version 1.0 suffers from a cross site scripting vulnerability.

CVE-2023-2907

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection.This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.

CVE-2022-47586: WordPress Ultimate Addons for Contact Form 7 plugin <= 3.1.23 - SQL Injection - Patchstack

Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.

CVE-2023-2805

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.