๐จ CVE-2022-41352
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavisd automatically prefers it over cpio.
๐@cveNotify
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavisd automatically prefers it over cpio.
๐@cveNotify
๐จ CVE-2022-41347
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
๐@cveNotify
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
๐@cveNotify
๐จ CVE-2022-21797
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
๐@cveNotify
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
๐@cveNotify
GitHub
FIX make sure pre_dispatch cannot do arbitrary code execution (#1321) ยท joblib/joblib@b90f10e
Computing with Python functions. Contribute to joblib/joblib development by creating an account on GitHub.
๐จ CVE-2022-21169
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
๐@cveNotify
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
๐@cveNotify
GitHub
fix XSS bypass by using prototype pollution issue. ยท AhmedAdelFahim/express-xss-sanitizer@3bf8aaa
Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. - fix XSS bypass by using prototype pollution issue. ยท AhmedAdelFahim/express-xss-sanitizer@3bf8aaa
๐จ CVE-2022-38553
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
๐@cveNotify
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
๐@cveNotify
CodeCanyon
Academy LMS - Learning Management System
Online learning marketplace script โ Academy. Academy Lms is a marketplace script for online learning. Here students and teachers are combined together for sharing knowledge...
๐จ CVE-2022-38341
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
๐@cveNotify
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
๐@cveNotify
๐จ CVE-2022-3301
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
๐@cveNotify
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
๐@cveNotify
huntr.dev
Improper Cleanup on Thrown Exception in rdiffweb
80 developers have been protected by securing rdiffweb. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
๐จ CVE-2022-38970
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.
๐@cveNotify
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.
๐@cveNotify
๐จ CVE-2022-36159
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.
๐@cveNotify
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.
๐@cveNotify
CONTEC
Overview / Features | FXA3200 | Simultaneous connection type Wireless LAN Access Point (Master Station) | CONTEC
This product has a built-in antenna in the housing, and is a compact access point that takes into consideration the installation environment and aesthetics, and simultaneously uses IEEE 802.11ac / n / a (5GHz band) and IEEE 802.11n / b / g (2.4GHz band).โฆ
๐จ CVE-2022-36158
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
๐@cveNotify
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
๐@cveNotify
๐จ CVE-2022-40925
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
๐@cveNotify
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
๐@cveNotify
GitHub
Bug_report/vendors/pushpam02/zoo-management-system/RCE-2.md at main ยท admin77888/Bug_report
Contribute to admin77888/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-40924
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
๐@cveNotify
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
๐@cveNotify
GitHub
Bug_report/vendors/pushpam02/zoo-management-system/RCE-1.md at main ยท admin77888/Bug_report
Contribute to admin77888/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-40404
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
๐@cveNotify
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
๐@cveNotify
GitHub
Bug_report/vendors/pushpam02/wedding-planner/SQLi-2.md at main ยท wshark00/Bug_report
Contribute to wshark00/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-40403
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
๐@cveNotify
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
๐@cveNotify
GitHub
Bug_report/vendors/pushpam02/wedding-planner/SQLi-3.md at main ยท wshark00/Bug_report
Contribute to wshark00/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-40402
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
๐@cveNotify
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
๐@cveNotify
GitHub
Bug_report/vendors/pushpam02/wedding-planner/SQLi-1.md at main ยท wshark00/Bug_report
Contribute to wshark00/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-3299
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. The name of the patch is 724fa568435dae45ef0c3a48b2aabde052afae88. It is recommended to apply a patch to fix this issue. The identifier VDB-209545 was assigned to this vulnerability.
๐@cveNotify
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. The name of the patch is 724fa568435dae45ef0c3a48b2aabde052afae88. It is recommended to apply a patch to fix this issue. The identifier VDB-209545 was assigned to this vulnerability.
๐@cveNotify
GitHub
Fixed HTTP2 crashes for random JSON data (#1769) ยท open5gs/open5gs@724fa56
Open5GS is a C-language Open Source implementation for 5G Core and EPC, i.e. the core network of LTE/NR network (Release-16) - Fixed HTTP2 crashes for random JSON data (#1769) ยท open5gs/open5gs@724fa56
๐จ CVE-2022-40050
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
๐@cveNotify
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
๐@cveNotify
GitHub
repdosenotexist/request4cve.pdf at main ยท achiove/repdosenotexist
Contribute to achiove/repdosenotexist development by creating an account on GitHub.
๐จ CVE-2022-30004
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
๐@cveNotify
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
๐@cveNotify
SourceCodester
Online Market Place Site in PHP/OOP Free Source Code
Introduction This simple project is an Online Market Place Site in PHP. This is a web-based application project developed in PHP and MySQL Database. This project is an online platform that allows sellers to publish their selling items. This simple site wasโฆ
๐จ CVE-2022-40099
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.
๐@cveNotify
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.
๐@cveNotify
GitHub
Bug_report/vendors/mayuri_k/online-tours-travels-management-system/SQLi-3.md at main ยท WYB-signal/Bug_report
Contribute to WYB-signal/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-40098
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.
๐@cveNotify
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.
๐@cveNotify
GitHub
Bug_report/SQLi-2.md at main ยท WYB-signal/Bug_report
Contribute to WYB-signal/Bug_report development by creating an account on GitHub.
๐จ CVE-2022-40097
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.
๐@cveNotify
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.
๐@cveNotify
GitHub
Bug_report/SQLi-1.md at main ยท WYB-signal/Bug_report
Contribute to WYB-signal/Bug_report development by creating an account on GitHub.