Tag
#webkit
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
101+ News Portal version 1.0 suffers from a remote blind SQL injection vulnerability.
Music Gallery Site version 1.0 suffers from a cross site scripting vulnerability.
Medicine Tracker System version 1.0 suffers from a cross site scripting vulnerability.
Yoga Class Registration System version 1.0 suffers from a cross site scripting vulnerability.
Online Pizza Ordering System version 1.0 suffers from a remote SQL injection vulnerability.
Human Resources Management System version 1.0 suffers from a remote SQL injection vulnerability.
A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223336.