Show filters
285 Total Results
Displaying 41-50 of 285
Sort by:
Attacker Value
Unknown
CVE-2024-0415
Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250435.
0
Attacker Value
Unknown
CVE-2024-0411
Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250431.
0
Attacker Value
Unknown
CVE-2023-50035
Disclosure Date: December 29, 2023 (last updated January 06, 2024)
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
0
Attacker Value
Unknown
CVE-2023-23437
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak
0
Attacker Value
Unknown
CVE-2023-45394
Disclosure Date: October 20, 2023 (last updated October 31, 2023)
Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
0
Attacker Value
Unknown
CVE-2023-5587
Disclosure Date: October 15, 2023 (last updated November 06, 2023)
A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /vm/admin/doctors.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-242186 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-44075
Disclosure Date: October 04, 2023 (last updated October 09, 2023)
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
0
Attacker Value
Unknown
CVE-2023-43331
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0
Attacker Value
Unknown
CVE-2023-3935
Disclosure Date: September 13, 2023 (last updated January 26, 2024)
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
0
Attacker Value
Unknown
CVE-2023-4445
Disclosure Date: August 21, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20230811. Affected by this issue is some unknown functionality of the file product/1/1?test=1&test2=2&. The manipulation of the argument orderBy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237566 is the identifier assigned to this vulnerability.
0