Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.Read More ...
Continue ReadingJune 02, 2022
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive in ...
Continue ReadingJune 02, 2022
Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.Read More ...
Continue ReadingJune 02, 2022
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.Read More ...
Continue ReadingJune 02, 2022
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).Read More ...
Continue ReadingJune 02, 2022
A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.Rea ...
Continue ReadingJune 02, 2022
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.Read More ...
Continue ReadingJune 02, 2022
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.Read More ...
Continue ReadingJune 02, 2022
Back to Main