Show filters
3,812 Total Results
Displaying 361-370 of 3,812
Sort by:
Attacker Value
Unknown

CVE-2023-42359

Disclosure Date: September 18, 2023 (last updated February 25, 2025)
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.
Attacker Value
Unknown

CVE-2023-4965

Disclosure Date: September 14, 2023 (last updated February 25, 2025)
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.
Attacker Value
Unknown

CVE-2023-41593

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.
Attacker Value
Unknown

CVE-2023-36140

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
Attacker Value
Unknown

CVE-2023-41575

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
Attacker Value
Unknown

CVE-2023-41615

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
Attacker Value
Unknown

CVE-2023-41594

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.
Attacker Value
Unknown

CVE-2023-4480

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the privileges of the running process. Additionally, they may write files to arbitrary locations, provided the files pass the application’s mime-type and file extension validation. 
Attacker Value
Unknown

CVE-2023-2453

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a ‘.php’ file payload.
Attacker Value
Unknown

CVE-2023-41539

Disclosure Date: August 30, 2023 (last updated February 25, 2025)
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.