Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Senayan Library Management System 9.2.1 SQL Injection

Senayan Library Management System version 9.2.1 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#vulnerability#web#git#auth
CVE-2022-43887: Security Bulletin: IBM Cognos Analytics has addressed multiple vulnerabilities (CVE-2021-29469, CVE-2022-39160, CVE-2022-38708, CVE-2022-42003, CVE-2022-42004, CVE-2022-43883, CVE-2022-43887, CVE-2022

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450.

CVE-2022-45041

SQL Injection exits in xinhu < 2.5.0

CVE-2022-47512: SolarWinds Platform 2022.4.1 Release Notes

Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected

CVE-2021-4262: preventing sql injection by wuwx · Pull Request #72 · mgallegos/laravel-jqgrid

A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.

CVE-2022-4050

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2021-4261: Release v1.0.6 · platzhersh/pacman-canvas

A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 1.0.6 is able to address this issue. The name of the patch is 29522c90ca1cebfce6453a5af5a45281d99b0646. It is recommended to upgrade the affected component. VDB-216270 is the identifier assigned to this vulnerability.

Senayan Library Management System 9.2.0 SQL Injection

Senayan Library Management System version 9.2.0 suffers from a remote SQL Injection vulnerability.

Senayan Library Management System 9.1.1 SQL Injection

Senayan Library Management System version 9.1.1 suffers from a remote SQL injection vulnerability.

GHSA-4jv9-3563-23j3: Knex.js has a limited SQL injection vulnerability

Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.