Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-35782: SQL Injection in extension "ipandlanguageredirect" (ipandlanguageredirect)

The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.

CVE
#sql#vulnerability#perl
CVE-2023-32754: 思考軟體科技 Efence - SQL injection

Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.

Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass Attack

Progress Software on Thursday disclosed a third vulnerability impacting its MOVEit Transfer application, as the Cl0p cybercrime gang deployed extortion tactics against affected companies. The new flaw, which is yet to be assigned a CVE identifier, also concerns an SQL injection vulnerability that "could lead to escalated privileges and potential unauthorized access to the environment." The

CVE-2023-32027

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-32026

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-29356

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-32025

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-2080: Forcepoint Customer Hub

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.

CVE-2023-31672: [CVE-2023-31672] Improper neutralization of an SQL parameter in ailinear module for PrestaShop

In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.