Show filters
4,018 Total Results
Displaying 111-120 of 4,018
Sort by:
Attacker Value
Unknown

CVE-2024-5413

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details.
0
Attacker Value
Unknown

CVE-2024-5312

Disclosure Date: May 24, 2024 (last updated May 24, 2024)
PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details.
0
Attacker Value
Unknown

CVE-2024-4826

Disclosure Date: May 16, 2024 (last updated May 17, 2024)
SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file.
0
Attacker Value
Unknown

CVE-2024-3096

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
0
Attacker Value
Unknown

CVE-2024-2757

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.
0
Attacker Value
Unknown

CVE-2024-2756

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
0
Attacker Value
Unknown

CVE-2024-1874

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
0
Attacker Value
Unknown

CVE-2024-2653

Disclosure Date: April 03, 2024 (last updated April 10, 2024)
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.
0
Attacker Value
Unknown

CVE-2024-3225

Disclosure Date: April 03, 2024 (last updated February 19, 2025)
A vulnerability was found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit-task.php. The manipulation of the argument task_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259070 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-3224

Disclosure Date: April 03, 2024 (last updated February 19, 2025)
A vulnerability has been found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259069 was assigned to this vulnerability.