Show filters
4,018 Total Results
Displaying 191-200 of 4,018
Sort by:
Attacker Value
Unknown
CVE-2023-43144
Disclosure Date: September 22, 2023 (last updated February 25, 2025)
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
0
Attacker Value
Unknown
CVE-2023-43274
Disclosure Date: September 21, 2023 (last updated February 25, 2025)
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2023-38876
Disclosure Date: September 20, 2023 (last updated February 25, 2025)
A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.
0
Attacker Value
Unknown
CVE-2023-38875
Disclosure Date: September 20, 2023 (last updated February 25, 2025)
A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.
0
Attacker Value
Unknown
CVE-2023-40619
Disclosure Date: September 20, 2023 (last updated February 25, 2025)
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized.
0
Attacker Value
Unknown
CVE-2023-42359
Disclosure Date: September 18, 2023 (last updated February 25, 2025)
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.
0
Attacker Value
Unknown
CVE-2023-4994
Disclosure Date: September 16, 2023 (last updated October 08, 2023)
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.
0
Attacker Value
Unknown
CVE-2023-38912
Disclosure Date: September 14, 2023 (last updated February 25, 2025)
SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.
0
Attacker Value
Unknown
CVE-2023-4965
Disclosure Date: September 14, 2023 (last updated February 25, 2025)
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.
0
Attacker Value
Unknown
CVE-2023-4480
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the privileges of the running process. Additionally, they may write files to arbitrary locations, provided the files pass the application’s mime-type and file extension validation.
0