Aggregator
CVE-2024-10355 | SourceCodester Petrol Pump Management Software 1.0 /admin/invoice.php id sql injection
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoice.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2024-10355. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10354 | SourceCodester Petrol Pump Management Software 1.0 /admin/print.php id sql injection
1 year 7 months ago
A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/print.php. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2024-10354. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-20424 (CVSS 9.9): 思科 FMC 软件漏洞为攻击者提供 Root 访问权限
1 year 7 months ago
安全客
Submit #430077: SourceCodester Petrol Pump Management Software 1.0 invoice.php SQL Injection [Accepted]
1 year 7 months ago
Submit #430077 / VDB-281702
K1nako
Submit #430074: SourceCodester Petrol Pump Management Software 1.0 print.php SQL Injection [Accepted]
1 year 7 months ago
Submit #430074 / VDB-281701
K1nako
CVE-2024-10353 | SourceCodester Online Exam System 1.0 /admin-dashboard access control
1 year 7 months ago
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-10353. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
This affects a different product and is a different issue than CVE-2024-40480.
vuldb.com
Submit #430054: SourceCodester Petrol Pump Management Software service_crud.php 1.0 Unrestricted Upload [Duplicate]
1 year 7 months ago
Submit #430054 / VDB-255374
K1nako
日本电产精密公司披露安全事件和数据泄露情况
1 year 7 months ago
安全客
Submit #430029: SourceCodester Petrol Pump Management Software 1.0 Unrestricted Upload [Duplicate]
1 year 7 months ago
Submit #430029 / VDB-255456
K1nako
JetBrains Rider 和 WebStorm 允许非商业用户免费使用
1 year 7 months ago
捷克的软件开发商 JetBrains 宣布,用于.NET 开发、以及 Unity (C#) 和 Unreal Engine (C++)游戏开发的 IDE Rider 和 Web, JavaScript 和 TypeScript 的 IDE WebStorm 允许非商业用户免费使用。JetBrains 称,今年早些时候,IDE RustRover 和 Aqua 实施了一种新的许可模式,即面向非商业用途免费提供。现在这一模式扩展到 WebStorm 和 Rider。如果用户将这些 IDE 用于非商业用途,例如学习、开源项目开发、内容创建或业余爱好开发,那么现在可以免费使用这些 IDE。这项变动不涉及商业项目,它将继续实施现有的许可模式。其他 JetBrains IDE 也不受此更新的影响。它将根据效果判断是否可以推广带其它 IDE。
CVE-2024-10351 | Tenda RX9 Pro 22.03.02.20 POST Request /goform/setMacFilterCfg sub_424CE0 deviceList stack-based overflow
1 year 7 months ago
A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-10351. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #427957: Sourcecodester Online Exam system using Django V 1.0 Improper Access Controls [Accepted]
1 year 7 months ago
Submit #427957 / VDB-281700
TheRaghul
CVE-2024-10350 | code-projects Hospital Management System 1.0 /admin/add-doctor.php docname sql injection
1 year 7 months ago
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection.
This vulnerability was named CVE-2024-10350. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
msldap:一款用于审计MS AD的LDAP库
1 year 7 months ago
msldap是一款用于审计MS AD的LDAP库,广大研究人员可以利用该工具轻松执行针对MS AD的安全审计任务。
Submit #427706: Tenda Rx9 Router RX9 Pro Firmware V22.03.02.20 Stack-based Buffer Overflow [Accepted]
1 year 7 months ago
Submit #427706 / VDB-281699
GuoXB
Submit #427705: code-projects Responsive Hotel Site Using PHP 1.0 sql [Accepted]
1 year 7 months ago
Submit #427705 / VDB-281698
R7Shell
hnb659fds: опасная привычка, ставшая ключом для доступа к AWS
1 year 7 months ago
Обычное упущение послужило отправной точкой для масштабных атак.
Perfctl 恶意软件再度来袭,加密骗子瞄准 Docker 远程 API 服务器
1 year 7 months ago
安全客
CVE-2024-10348 | SourceCodester Best House Rental Management System 1.0 Manage Tenant Details /index.php?page=tenants Last Name/First Name/Middle Name cross site scripting
1 year 7 months ago
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the component Manage Tenant Details. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10348. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The initial researcher advisory only shows the field "Last Name" to be affected. Other fields might be affected as well.
vuldb.com