Show filters
3,812 Total Results
Displaying 391-400 of 3,812
Sort by:
Attacker Value
Unknown
CVE-2023-40749
Disclosure Date: August 28, 2023 (last updated February 25, 2025)
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
0
Attacker Value
Unknown
CVE-2023-40748
Disclosure Date: August 28, 2023 (last updated February 25, 2025)
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
0
Attacker Value
Unknown
CVE-2023-38890
Disclosure Date: August 18, 2023 (last updated February 25, 2025)
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.
0
Attacker Value
Unknown
CVE-2023-27576
Disclosure Date: August 18, 2023 (last updated February 25, 2025)
An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission. Specifically, for a request with updatepassword=1, a modified request (manipulating both the ID parameter and the associated username) can bypass the intended email confirmation requirement. For example, the attacker can start from an updatepassword=1 request with their own ID number, and change the ID number to 1 (representing the super admin account) and change the username to admin2. In the first step, the attacker changes the super admin's email address to one under the attacker's control. In the second step, the attacker performs a password reset for the super admin account. The new password allows login as the super admin, i.e., a successful account takeover.
0
Attacker Value
Unknown
CVE-2023-28783
Disclosure Date: August 17, 2023 (last updated February 25, 2025)
Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2 versions.
0
Attacker Value
Unknown
CVE-2023-4371
Disclosure Date: August 15, 2023 (last updated February 25, 2025)
A vulnerability was found in phpRecDB 1.3.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument r/view leads to cross site scripting. The attack may be launched remotely. VDB-237194 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-3824
Disclosure Date: August 11, 2023 (last updated February 25, 2025)
In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.
0
Attacker Value
Unknown
CVE-2023-3823
Disclosure Date: August 11, 2023 (last updated February 25, 2025)
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.
0
Attacker Value
Unknown
CVE-2023-36315
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0.
0
Attacker Value
Unknown
CVE-2023-36314
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.
0