Show filters
3,812 Total Results
Displaying 331-340 of 3,812
Sort by:
Attacker Value
Unknown
CVE-2023-5199
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.
0
Attacker Value
Unknown
CVE-2023-5804
Disclosure Date: October 26, 2023 (last updated February 25, 2025)
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The identifier VDB-243617 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-5794
Disclosure Date: October 26, 2023 (last updated February 25, 2025)
A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-243600.
0
Attacker Value
Unknown
CVE-2023-46584
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.
0
Attacker Value
Unknown
CVE-2023-46583
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.
0
Attacker Value
Unknown
CVE-2023-45639
Disclosure Date: October 16, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Codex-m Sort SearchResult By Title plugin <= 10.0 versions.
0
Attacker Value
Unknown
CVE-2023-43147
Disclosure Date: October 12, 2023 (last updated February 25, 2025)
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
0
Attacker Value
Unknown
CVE-2023-36127
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
0
Attacker Value
Unknown
CVE-2023-36126
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
0
Attacker Value
Unknown
CVE-2023-41580
Disclosure Date: October 02, 2023 (last updated February 25, 2025)
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
0