Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

My Neighbor's Flat Smells Like Data

Whitepaper on hacking smart switches to capture credentials for a network.

Packet Storm
#vulnerability#vulnerability#vulnerability#vulnerability#vulnerability#sql#vulnerability#vulnerability#vulnerability#dos#vulnerability#vulnerability
Froxlor 0.10.29.1 SQL Injection

Froxlor version 0.10.2l9.1 suffers from a remote SQL injection vulnerability that can enable an attacker to achieve remote code execution.

CVE-2021-28022: Help Desk Software for your company | ServiceTonic

Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.

CVE-2021-42077: PHP Event Calendar Lite Edition SQL Injection ≈ Packet Storm

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.