Show filters
1,999 Total Results
Displaying 91-100 of 1,999
Sort by:
Attacker Value
Unknown
CVE-2024-25218
Disclosure Date: February 14, 2024 (last updated February 17, 2024)
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php.
0
Attacker Value
Unknown
CVE-2024-25191
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
0
Attacker Value
Unknown
CVE-2024-24398
Disclosure Date: February 06, 2024 (last updated February 14, 2024)
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
0
Attacker Value
Unknown
CVE-2024-24945
Disclosure Date: February 01, 2024 (last updated February 08, 2024)
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.
0
Attacker Value
Unknown
CVE-2024-24041
Disclosure Date: February 01, 2024 (last updated February 08, 2024)
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
0
Attacker Value
Unknown
CVE-2024-22922
Disclosure Date: January 25, 2024 (last updated January 30, 2024)
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
0
Attacker Value
Unknown
CVE-2023-6551
Disclosure Date: January 04, 2024 (last updated October 10, 2024)
As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used.
Developers must be aware of that fact and use extension whitelisting accompanied by forcing the server to always provide content-type based on the file extension.
The README has been updated to include these guidelines.
0
Attacker Value
Unknown
CVE-2023-52086
Disclosure Date: December 26, 2023 (last updated January 04, 2024)
resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)
0
Attacker Value
Unknown
CVE-2023-50252
Disclosure Date: December 12, 2023 (last updated December 16, 2023)
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially when the `href` attribute from the `<use>` tag has not been sanitized. This can lead to an unsafe file read that can cause PHAR Deserialization vulnerability in PHP prior to version 8. Version 0.5.1 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2023-50251
Disclosure Date: December 12, 2023 (last updated December 16, 2023)
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.
0