‼ CVE-2022-44788 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after a successful login.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44785 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-43709 ‼
📖 Read
via "National Vulnerability Database".
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41945 ‼
📖 Read
via "National Vulnerability Database".
super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ??into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40765 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30529 ‼
📖 Read
via "National Vulnerability Database".
File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-43685 ‼
📖 Read
via "National Vulnerability Database".
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41936 ‼
📖 Read
via "National Vulnerability Database".
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized users are exposed though the `modifications` rest endpoint (comments and page names etc). Users should upgrade to XWiki 14.6+, 14.4.3+, or 13.10.8+. Older versions have not been patched. There are no known workarounds.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36227 ‼
📖 Read
via "National Vulnerability Database".
In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference or, in some cases, even arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41223 ‼
📖 Read
via "National Vulnerability Database".
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41940 ‼
📖 Read
via "National Vulnerability Database".
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-35407 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable exceeds the size of the first, then the buffer will be overwritten. This issue affects the SetupUtility driver of InsydeH2O.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-43214 ‼
📖 Read
via "National Vulnerability Database".
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36179 ‼
📖 Read
via "National Vulnerability Database".
Fusiondirectory 1.3 suffers from Improper Session Handling.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40842 ‼
📖 Read
via "National Vulnerability Database".
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41326 ‼
📖 Read
via "National Vulnerability Database".
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-41937 ‼
📖 Read
via "National Vulnerability Database".
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8. As a workaround, setting the right of the page Filter.WebHome and making sure only the main wiki administrators can view the application installed on main wiki or edit the page and apply the changed described in commit fb49b4f.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-43215 ‼
📖 Read
via "National Vulnerability Database".
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40602 ‼
📖 Read
via "National Vulnerability Database".
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37931 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-36180 ‼
📖 Read
via "National Vulnerability Database".
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.📖 Read
via "National Vulnerability Database".