Show filters
1,297 Total Results
Displaying 141-150 of 1,297
Sort by:
Attacker Value
Unknown
CVE-2023-3659
Disclosure Date: July 13, 2023 (last updated October 08, 2023)
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234013 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-3658
Disclosure Date: July 13, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-234012.
0
Attacker Value
Unknown
CVE-2023-3657
Disclosure Date: July 13, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-234011.
0
Attacker Value
Unknown
CVE-2023-37415
Disclosure Date: July 13, 2023 (last updated February 14, 2025)
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.
Patching on top of CVE-2023-35797
Before 6.1.2 the proxy_user option can also inject semicolon.
This issue affects Apache Airflow Apache Hive Provider: before 6.1.2.
It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.
0
Attacker Value
Unknown
CVE-2023-36543
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected
0
Attacker Value
Unknown
CVE-2023-35908
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
0
Attacker Value
Unknown
CVE-2023-22888
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to upgrade to a version that is not affected
0
Attacker Value
Unknown
CVE-2023-22887
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to upgrade to a version that is not affected
0
Attacker Value
Unknown
CVE-2022-46651
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it. Users should upgrade to version 2.6.3 or later which has removed the vulnerability.
0
Attacker Value
Unknown
CVE-2023-3619
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue affects some unknown processing of the file Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The identifier VDB-233573 was assigned to this vulnerability.
0