Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Ubuntu Security Notice USN-4781-2

Ubuntu Security Notice 4781-2 - USN-4781-1 fixed several vulnerabilities in Slurm. This update provides the corresponding updates for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. It was discovered that Slurm incorrectly handled certain messages between the daemon and the user. An attacker could possibly use this issue to assume control of an arbitrary file on the system. This issue only affected Ubuntu 16.04 ESM.

Packet Storm
#sql#vulnerability#ubuntu#linux#perl
eCommerce Marketplace Platform CMS 1.7 SQL Injection

eCommerce Marketplace Platform CMS version 1.7 suffers from a remote SQL injection vulnerability.

eCommerce Marketplace Platform CMS 1.7 Cross Site Scripting

eCommerce Marketplace Platform CMS version 1.7 suffers from a cross site scripting vulnerability.

CVE-2022-47769: Security Advisory: Serenissima Informatica – FastCheckIn (CVE-2022-47768/CVE-2022-47769/ CVE-2022-47770)

An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

CVE-2022-47770: Internet Speed Test

Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.

CVE-2023-24956: Forget Heart Message Box 1.1 has multiple SQL injections · Issue #1 · Mortalwangxin/lives

Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.

CVE-2022-45297: GitHub - tlfyyds/EQ

EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.

Hikvision Remote Code Execution / XSS / SQL Injection

Some Hikvision Hybrid SAN products were vulnerable to multiple remote code execution (command injection) vulnerabilities, including reflected cross site scripting, Ruby code injection, classic and blind SQL injection resulting in remote code execution that allows an adversary to execute arbitrary operating system commands and more. However, an adversary must be on the same network to leverage this vulnerability to execute arbitrary commands.

PHPJabbers Business Directory Script 3.2 Cross Site Scripting

PHPJabbers Business Directory Script version 3.2 suffers from a cross site scripting vulnerability.