Tag
#windows
Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.
SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
OutSystems Service Studio version 11.53.30 suffers from a dll hijacking vulnerability.
i2soft CMS version 2.0 suffers from an insecure direct object reference vulnerability.
helloGTX Travel Portal CRM version 1.6 suffers from an insecure direct object reference vulnerability.
FlatApp Premium Admin Dashboard version 1.0 suffers from a remote SQL injection vulnerability.
Greeva version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.