π¨ CVE-2022-1905
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
π@cveNotify
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
π@cveNotify
π¨ CVE-2022-1896
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.
π@cveNotify
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.
π@cveNotify
π¨ CVE-2022-1895
The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
π@cveNotify
The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
π@cveNotify
π¨ CVE-2022-1889
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
π@cveNotify
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
π@cveNotify
π¨ CVE-2022-32278
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
π@cveNotify
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
π@cveNotify
GitLab
exo-open : Only execute local .desktop files (c71c04ff) Β· Commits Β· Xfce / exo Β· GitLab
Issue #85 (Backported cc047717) CVE-2022-32278 This patch prevents executing possibly malicious .desktop files from online sources (ftp://, http:// etc.). Original patch authored by Alexander Schwinn
π¨ CVE-2022-25772
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
π@cveNotify
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
π@cveNotify
GitHub
XSS vulnerability in tracking pixel functionality
### Impact
Mautic allows you to track open rates by using tracking pixels.
The tracking information is stored together with extra metadata of the tracking request.
The output isn't suff...
Mautic allows you to track open rates by using tracking pixels.
The tracking information is stored together with extra metadata of the tracking request.
The output isn't suff...
π¨ CVE-2022-31795
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.
π@cveNotify
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.
π@cveNotify
NCC Group Research Blog
Technical Advisory β FUJITSU CentricStor Control Center <= V8.1 β Unauthenticated Command Injection ( CVE-2022-31794 and CVE-2022β¦
On the 6th of April 2022, NCC Groupβs Fox-IT discovered two separate flaws in FUJITSU CentricStor Control Center V8.1 which allows an attacker to gain remote code execution on the appliance wβ¦
π¨ CVE-2022-31794
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.
π@cveNotify
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.
π@cveNotify
NCC Group Research Blog
Technical Advisory β FUJITSU CentricStor Control Center <= V8.1 β Unauthenticated Command Injection ( CVE-2022-31794 and CVE-2022β¦
On the 6th of April 2022, NCC Groupβs Fox-IT discovered two separate flaws in FUJITSU CentricStor Control Center V8.1 which allows an attacker to gain remote code execution on the appliance wβ¦
π¨ CVE-2022-2134
Denial of Service in GitHub repository inventree/inventree prior to 0.8.0.
π@cveNotify
Denial of Service in GitHub repository inventree/inventree prior to 0.8.0.
π@cveNotify
π¨ CVE-2022-1720
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
π@cveNotify
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
π@cveNotify
GitHub
patch 8.2.4956: reading past end of line with "gf" in Visual block mode Β· vim/vim@395bd1f
Problem: Reading past end of line with "gf" in Visual block mode.
Solution: Do not include the NUL in the length.
Solution: Do not include the NUL in the length.
π¨ CVE-2022-33913
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
π@cveNotify
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
π@cveNotify
mahara.org
Security Announcements - Information disclosure in Mahara before 21.04.6, 21.10.4, and 22.04.2 and all versions of 20.04 and 20.10β¦
Mahara is an open source ePortfolio and social networking web application.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
π¨ CVE-2022-32983
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
π@cveNotify
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
π@cveNotify
π¨ CVE-2017-20066
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
π@cveNotify
seclists.org
Full Disclosure: WordPress Adminer plugin allows public (local) database login
π¨ CVE-2017-20065
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
seclists.org
Full Disclosure: Popup by Supsystic WordPress plugin vulnerable to Cross-Site Request Forgery
π¨ CVE-2022-29501
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
π@cveNotify
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
π@cveNotify
π¨ CVE-2022-29500
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
π@cveNotify
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
π@cveNotify
π¨ CVE-2022-31062
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.
π@cveNotify
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.
π@cveNotify
GitHub
Unauthenticated Local File Inclusion
### Impact
A plugin public script can be used to read content of system files.
### Patches
Upgrade to version 1.0.2.
### Workarounds
`b/deploy/index.php` file can be deleted if deploy feat...
A plugin public script can be used to read content of system files.
### Patches
Upgrade to version 1.0.2.
### Workarounds
`b/deploy/index.php` file can be deleted if deploy feat...
π¨ CVE-2015-20107
In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments).
π@cveNotify
In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments).
π@cveNotify
GitHub
[CVE-2015-20107] mailcap.findmatch: document shell command Injection danger in filename parameter Β· Issue #68966 Β· python/cpython
BPO 24778 Nosy @vstinner, @bitdancer Files screenshot.pngThe Quote Problem.pymailcap patch.zip: mailcap.py patches and diffs for python2.7 and python 3.5 Note: these values reflect the state of the...
π¨ CVE-2017-20081
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/reports.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/reports.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
Vuldb
CVE-2017-20081 | Hindu Matrimonial Script reports.php privileges management (EDB-41044 / EDB-41044)
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This vulnerability is uniquely identified as CVE-2017-20081.
π¨ CVE-2017-20080
A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
Exploit Database
Hindu Matrimonial Script - Authentication Bypass
Hindu Matrimonial Script - Authentication Bypass.. webapps exploit for PHP platform
π¨ CVE-2017-20079
A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
Exploit Database
Hindu Matrimonial Script - Authentication Bypass
Hindu Matrimonial Script - Authentication Bypass.. webapps exploit for PHP platform