Tag
#webkit
SPIP version 4.2.11 suffers from a code execution vulnerability.
Bang Resto version 1.0 suffers from an information disclosure vulnerability.
DiCal-RED version 4009 has an administrative web interface that is vulnerable to path traversal attacks in several places. The functions to download or display log files can be used to access arbitrary files on the device's file system. The upload function for new license files can be used to write files anywhere on the device's file system - possibly overwriting important system configuration files, binaries or scripts. Replacing files that are executed during system operation results in a full compromise of the whole device.
Simple Machines Forum version 2.1.4 suffers from an authenticated code injection vulnerability.
Build Your Own Botnet (BYOB) version 2.0.0 exploit that works by spoofing an agent callback to overwrite the sqlite database and bypass authentication and exploiting an authenticated command injection in the payload builder page.
Computer Laboratory Management version 1.0 suffers from a remote authenticated SQL injection vulnerability.
WordPress PayPlus Payment Gateway plugin versions prior to 6.6.9 suffer from a remote SQL injection vulnerability.
Online Shopping Portal Project version 2.0 suffers from a remote SQL injection vulnerability.
Leads Manager Tool suffers from remote SQL injection and cross site scripting vulnerabilities.
Apple Security Advisory 07-29-2024-9 - visionOS 1.3 addresses bypass, information leakage, integer overflow, out of bounds access, out of bounds read, and use-after-free vulnerabilities.