Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-33945: CVE-2023-33945 SQL injection in SQL Server upgrades - Liferay

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.

CVE
#sql#vulnerability#web
thrsrossi Millhouse-Project 1.414 Shell Upload

thrsrossi Millhouse-Project version 1.414 suffers from a remote shell upload vulnerability.

eScan Management Console 14.0.1400.2281 SQL Injection

eScan Management Console version 14.0.1400.2281 suffers from a remote SQL injection vulnerability.

Quicklancer 1.0 SQL Injection

Quicklancer version 1.0 suffers from a remote SQL injection vulnerability.

Smart School 1.0 SQL Injection

Smart School version 1.0 suffers from a remote SQL injection vulnerability.

LeadPro CRM 1.0 SQL Injection

LeadPro CRM version 1.0 suffers from a remote SQL injection vulnerability.

CVE-2023-2045

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection.This issue affects Auto Damage Tracking Software: before 4.

CVE-2023-2064

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection.This issue affects eTrace: before 23.05.20.

CVE-2023-2750

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection.This issue affects E-municipality: before 6.05.