Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2020-28246: GitHub - formio/formio: A Form and Data Management Platform for Progressive Web Applications.

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL.

CVE
#web#mac#windows#nodejs#js#git#rce#auth#mongo#docker
CVE-2022-31342: bug_report/delete-file-1.md at main · k0xx11/bug_report

Online Car Wash Booking System v1.0 is vulnerable to Delete any file via /ocwbs/classes/Master.php?f=delete_img.

CVE-2022-31962: bug_report/SQLi-9.md at main · k0xx11/bug_report

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/view_incident.php?id=.

CVE-2022-30808: bug_report/RCE-1.md at main · k0xx11/bug_report

elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

CVE-2022-31344: bug_report/SQLi-3.md at main · k0xx11/bug_report

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_booking.

CVE-2022-31964: bug_report/SQLi-11.md at main · k0xx11/bug_report

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/respondent_types/view_respondent_type.php?id=.

CVE-2022-31961: bug_report/SQLi-10.md at main · k0xx11/bug_report

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/manage_incident.php?id=.

CVE-2022-31343: bug_report/SQLi-1.md at main · k0xx11/bug_report

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=.

CVE-2022-31345: bug_report/SQLi-2.md at main · k0xx11/bug_report

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=.