Aggregator
How One Tiny IDOR Created a Digital Domino Effect That Toppled Their Entire Security
7 months ago
Karmic Security — HTB Starting Point: Appointment
7 months ago
Hello and welcome to Starting Point Tier 1! We are officially out of tier zero and are now actually
Hack the Box Starting Point: Responder
7 months ago
Hello and welcome back to the little Starting Point series I’ve been doing on the HacktheBox main pl
CVE-2007-0821 | PortailPHP mod_news/goodies.php Remote Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. Local Privilege Escalation (EDB-29563 / BID-22381)
7 months ago
A vulnerability has been found in PortailPHP and classified as problematic. Impacted is an unknown function of the file mod_news/goodies.php. This manipulation of the argument Remote causes Local Privilege Escalation.
This vulnerability is registered as CVE-2007-0821. The attack needs to be launched locally. Furthermore, an exploit is available.
vuldb.com
CVE-2007-0821 | Cedric CLAIRE PortailPhp 2 mod_news/index.php chemin Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. path traversal (EDB-29563 / BID-22381)
7 months ago
A vulnerability described as problematic has been identified in Cedric CLAIRE PortailPhp 2. Impacted is an unknown function of the file mod_news/index.php of the component mod_news/index.php. Such manipulation of the argument chemin leads to path traversal.
This vulnerability is documented as CVE-2007-0821. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2007-0821 | PortailPHP mod_news/goodies.php chemin Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. path traversal (EDB-29563 / BID-22381)
7 months ago
A vulnerability has been found in PortailPHP and classified as problematic. This affects an unknown function of the file mod_news/goodies.php of the component mod_news/goodies.php. Performing manipulation of the argument chemin results in path traversal.
This vulnerability is cataloged as CVE-2007-0821. The attack must be initiated from a local position. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0699 | Portail Web Php up to 2.5.1.0 includes/includes.php site_path Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. code injection (EDB-3250 / XFDB-32121)
7 months ago
A vulnerability classified as critical was found in Portail Web Php up to 2.5.1.0. This vulnerability affects unknown code of the file includes/includes.php. The manipulation of the argument site_path results in code injection.
This vulnerability was named CVE-2007-0699. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2007-0820 | Cedric CLAIRE PortailPhp 2 mod_news/index.php chemin Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. file inclusion (EDB-29565 / XFDB-42123)
7 months ago
A vulnerability marked as critical has been reported in Cedric CLAIRE PortailPhp 2. This issue affects some unknown processing of the file mod_news/index.php of the component mod_news/index.php. This manipulation of the argument chemin causes file inclusion.
This vulnerability is registered as CVE-2007-0820. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2007-0820 | PortailPHP mod_search/index.php Remote Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. Remote Code Execution (EDB-29565 / XFDB-42123)
7 months ago
A vulnerability was found in PortailPHP and classified as critical. The affected element is an unknown function of the file mod_search/index.php. Such manipulation of the argument Remote leads to Remote Code Execution.
This vulnerability is documented as CVE-2007-0820. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-13577 | PHPGurukul Hostel Management System 2.1 /register-complaint.php cdetails cross site scripting (EUVD-2025-198597)
7 months ago
A vulnerability classified as problematic was found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing manipulation of the argument cdetails can lead to cross site scripting.
This vulnerability is registered as CVE-2025-13577. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
Молчание — золото (но не биткоины). Подрядчик итальянских железных дорог «слил» в даркнет 2,3 терабайта документов
7 months ago
Вся внутренняя кухня FS Italiane теперь в руках хакеров.
CVE-2025-13576 | code-projects Blog Site 1.0 /admin.php improper authorization (EUVD-2025-198595)
7 months ago
A vulnerability classified as critical has been found in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2025-13576. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Multiple endpoints are affected.
vuldb.com
CVE-2025-13575 | code-projects Blog Site 1.0 Category blog.php category_exists name/field sql injection (EUVD-2025-198596)
7 months ago
A vulnerability described as critical has been identified in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql injection.
This vulnerability is listed as CVE-2025-13575. The attack may be performed from remote. In addition, an exploit is available.
Multiple endpoints are affected.
vuldb.com
Submit #698995: PHPGurukul Hostel Management System 2.1 Stored Cross Site Scripting [Accepted]
7 months ago
Submit #698995 / VDB-333341
harun.tamokur
Submit #698772: https://code-projects.org/ Blog Site In PHP With Source Code 1.0 Unauthorized [Accepted]
7 months ago
Submit #698772 / VDB-333340
Yohane-Mashiro
Submit #698771: https://code-projects.org/ blog site in php with source code 1.0 SQL Injection [Duplicate]
7 months ago
Submit #698771 / VDB-333339
Yohane-Mashiro
Submit #698769: https://code-projects.org/ blog site in php with source code 1.0 SQL Injection [Accepted]
7 months ago
Submit #698769 / VDB-333339
Yohane-Mashiro
CVE-2025-13574 | code-projects Online Bidding System 1.0 addcategory.php categoryadd catimage unrestricted upload (EUVD-2025-198593 / CNNVD-202511-2587)
7 months ago
A vulnerability marked as critical has been reported in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload.
This vulnerability is tracked as CVE-2025-13574. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2023-31082 | Linux Kernel 6.2 drivers/tty/n_gsm.c sleeping Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. denial of service (Nessus ID 276493)
7 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel 6.2. This issue affects the function sleeping of the file drivers/tty/n_gsm.c. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-31082. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com