Aggregator
随便聊聊安全建设当前现状
9 months 2 weeks ago
CVE-2024-10842 | romadebrian WEB-Sekolah 1.0 Backend Proses_Edit_Akun.php Username_Baru/Password cross site scripting
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file /Admin/Proses_Edit_Akun.php of the component Backend. The manipulation of the argument Username_Baru/Password leads to cross site scripting.
This vulnerability is handled as CVE-2024-10842. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10841 | romadebrian WEB-Sekolah 1.0 Mail /Proses_Kirim.php Name sql injection
9 months 2 weeks ago
A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name leads to sql injection.
This vulnerability is known as CVE-2024-10841. The attack can be launched remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2024-10840 | romadebrian WEB-Sekolah 1.0 Backend /Admin/akun_edit.php kode cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting.
This vulnerability is traded as CVE-2024-10840. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-37847 | MangoOS up to 5.1.3 API unrestricted upload
9 months 2 weeks ago
A vulnerability was found in MangoOS up to 5.1.3 and classified as critical. This issue affects some unknown processing of the component API. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-37847. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7807 | gaizhenbiao ChuanhuChatGPT 20240305/20240310/20240410 resource consumption
9 months 2 weeks ago
A vulnerability was found in gaizhenbiao ChuanhuChatGPT 20240305/20240310/20240410 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-7807. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52066 | http.zig 76cf5 Parameter url injection (Issue 25)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in http.zig 76cf5. This affects an unknown part of the component Parameter Handler. The manipulation of the argument url leads to injection.
This vulnerability is uniquely identified as CVE-2023-52066. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-48733 | SAS Studio 9.4 POST Body sql sql injection
9 months 2 weeks ago
A vulnerability was found in SAS Studio 9.4. It has been classified as critical. This affects an unknown part of the file /SASStudio/sasexec/sessions/{sessionID}/sql of the component POST Body Handler. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-48733. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-48734 | SAS Studio 9.4 {InternalPath} unrestricted upload
9 months 2 weeks ago
A vulnerability was found in SAS Studio 9.4. It has been declared as critical. This vulnerability affects unknown code of the file /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath}. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-48734. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50801 | AbanteCart 1.4.0 collections.php update id sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in AbanteCart 1.4.0. This affects the function update of the file public_html/admin/controller/responses/listing_grid/collections.php. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-50801. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50802 | AbanteCart 1.4.0 email_templates.php update id sql injection
9 months 2 weeks ago
A vulnerability has been found in AbanteCart 1.4.0 and classified as critical. This vulnerability affects the function update of the file public_html/admin/controller/responses/listing_grid/email_templates.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-50802. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10655 | Tongda OA 2017 up to 11.9 /pda/reportshop/new.php repid sql injection
9 months 2 weeks ago
A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file /pda/reportshop/new.php. The manipulation of the argument repid leads to sql injection.
This vulnerability was named CVE-2024-10655. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10656 | Tongda OA 2017 up to 11.9 /pda/meeting/apply.php mr_id sql injection
9 months 2 weeks ago
A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the file /pda/meeting/apply.php. The manipulation of the argument mr_id leads to sql injection.
The identification of this vulnerability is CVE-2024-10656. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-48270 | oasys 1.1 /logins information disclosure
9 months 2 weeks ago
A vulnerability classified as problematic was found in oasys 1.1. Affected by this vulnerability is an unknown functionality of the file /logins. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-48270. The attack needs to be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-51407 | Floodlight SDN OpenFlow Controller 1.2 Broadcast Port Local Privilege Escalation (ID 869)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Floodlight SDN OpenFlow Controller 1.2. This affects an unknown part of the component Broadcast Port Handler. The manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-51407. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-10598 | Tongda OA 11.2/11.3/11.4/11.5/11.6 Annual Leave data.php improper authorization
9 months 2 weeks ago
A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to improper authorization.
This vulnerability was named CVE-2024-10598. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10599 | Tongda OA 2017 up to 11.7 package_static_resources.php resource consumption
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the file /inc/package_static_resources.php. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2024-10599. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2024-10600 | Tongda OA 2017 up to 11.6 submenu.php appid sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. The manipulation of the argument appid leads to sql injection.
This vulnerability is traded as CVE-2024-10600. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10601 | Tongda OA 2017 up to 11.10 delete.php where_repeat sql injection
9 months 2 weeks ago
A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /general/address/private/address/query/delete.php. The manipulation of the argument where_repeat leads to sql injection.
This vulnerability is known as CVE-2024-10601. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com