Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Joomla JS Jobs Pro 1.3.6 SQL Injection

Joomla JS Jobs Pro extension version 1.3.6 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#vulnerability#web#js#php#auth
Joomla jMarket 5.15 Cross Site Scripting

Joomla jMarket extension version 5.15 suffers from a cross site scripting vulnerability.

CVE-2022-42002: Improving GraphQL security with static analysis and Snyk Code | Snyk

SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.

CVE-2022-40943: CVE/bwdate-report-ds-sql(CVE-2022-40943).md at main · Qrayyy/CVE

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2021-36865: Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress

Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.

CVE-2022-40756: Professional and Support Services

If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

CVE-2022-40944: Dairy Farm Shop Management System中的sales-report-ds.php存在sql注入 - 在谷底也要开花

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

CVE-2022-36965: SolarWinds Trust Center Security Advisories | CVE-2022-36965

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).

CVE-2022-36965: SolarWinds Platform 2022.3 Release Notes

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).

CVE-2022-36961: SolarWinds Trust Center Security Advisories | CVE-2022-36961

A verb used in Orion was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.