Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2022-32401: BugBounty/cve-2022-32401.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4

CVE
#sql#vulnerability#php
CVE-2022-32400: BugBounty/cve-2022-32400.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

CVE-2022-32396: BugBounty/cve-2022-32396.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4

CVE-2022-32391: BugBounty/cve-2022-32391.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

CVE-2022-32987: Simple Bakery Shop Management System in PHP MySQL

Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.

CVE-2021-40956: SQL injection exists in the LaiKetui menu management function · Issue #13 · bettershop/LaikeTui

LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

CVE-2021-26636: KISA 인터넷 보호나라&KrCERT

Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.

CVE-2022-31361: Security Advisory: Docebo Community Edition <= 4.0.5 - Swascan

** UNSUPPORTED WHEN ASSIGNED ** Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2021-40955: Background SQL injection · Issue #12 · bettershop/LaikeTui

SQL injection exists in LaiKetui v3.5.0 the background administrator list.