Aggregator
CVE-2025-7477 | code-projects Simple Car Rental System 1.0 /admin/add_cars.php image unrestricted upload
CVE-2025-7476 | code-projects Simple Car Rental System 1.0 /admin/approve.php ID sql injection
CVE-2025-7475 | code-projects Simple Car Rental System 1.0 /pay.php mpesa sql injection
CVE-2025-7474 | code-projects Job Diary 1.0 /search.php Search sql injection
Submit #610505: code-projects Modern Bag V1.0 SQL Injection [Accepted]
Submit #610439: code-projects Car Rental System 1.0 Unrestricted Upload [Accepted]
Submit #610433: code-projects Simple Car Rental System 1.0 SQL Injection [Accepted]
Submit #610432: code-projects Simple Car Rental System 1.0 SQL Injection [Accepted]
Submit #610135: code-projects Job Diary V1.0 SQL Injection [Accepted]
Fortinet FortiWeb Fabric Connector Vulnerability Exploited to Execute Remote Code
A critical security vulnerability in Fortinet’s FortiWeb Fabric Connector has been discovered and exploited, allowing attackers to execute remote code on affected systems without authentication. The vulnerability, designated CVE-2025-25257, represents a significant threat to organizations using Fortinet’s web application firewall solutions. Key Takeaways1. Fortinet FortiWeb Fabric Connector has an unauthenticated SQL injection (CVE-2025-25257) enabling remote […]
The post Fortinet FortiWeb Fabric Connector Vulnerability Exploited to Execute Remote Code appeared first on Cyber Security News.
Critical Wing FTP Server vulnerability exploited in the wild (CVE-2025-47812)
Threat actors are actively exploiting a recently fixed remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server, security researchers have warned. Wing FTP Server and CVE-2025-47812 Wing FTP Server is a commercial file transfer server solution used by businesses, MSPs and hosting providers. The software can be installed on 64-bit operating systems: Windows, Windows Server, Linux, and macOS. Administration is done via a web-based interface. Users likewise upload/download files securely via browser. CVE-2025-47812 is caused … More →
The post Critical Wing FTP Server vulnerability exploited in the wild (CVE-2025-47812) appeared first on Help Net Security.