Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2021-40317: [11.5.0]SQL Injection Vulnerability · Issue #1470 · Piwigo/Piwigo

Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.

CVE
#sql#vulnerability#mac#git#php
CVE-2022-29650: Online Food Ordering System Unauthenticated Sql Injection - HackMD

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

CVE-2022-1883: fix(db): possible sql injection on /search endpoint · camptocamp/terraboard@2a5dbaa

SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.

CVE-2022-29359: School Club Application System in PHP/OOP Free Source Code

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

Ubuntu Security Notice USN-5440-1

Ubuntu Security Notice 5440-1 - Alexander Lakhin discovered that PostgreSQL incorrectly handled the security restricted operation sandbox when a privileged user is maintaining another user's objects. An attacker having permission to create non-temp objects can use this issue to execute arbitrary commands as the superuser.

Online Fire Reporting System 1.0 SQL Injection

Online Fire Reporting System version 1.0 suffers from a remote SQL injection vulnerability.

CLink Office 2.0 SQL Injection

CLink Office version 2.0 anti-spam management console suffers from a remote SQL injection vulnerability.

CVE-2022-22495: IBM i SQL injection CVE-2022-22495 Vulnerability Report

IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.

CVE-2021-4230

A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings.

CVE-2013-10003

A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. The manipulation leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.