In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input paramete ...
Continue ReadingSeptember 14, 2022
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary ...
Continue ReadingSeptember 14, 2022
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component LeagueFlysystemCachedStoragePsr6Cache. This vulnerability allows attackers to execute arbitrary code via a ...
Continue ReadingSeptember 14, 2022
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.Read More ...
Continue ReadingSeptember 14, 2022
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.Read More ...
Continue ReadingSeptember 14, 2022
An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_By ...
Continue ReadingSeptember 14, 2022
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4CttsAtom.cpp.Read More ...
Continue ReadingSeptember 14, 2022
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Ex ...
Continue ReadingSeptember 14, 2022
Back to Main