CVE-2022-3949 - Exploiting XSS in Sourcecodester Simple Cashiering System via User Account Handler
In late 2022, a medium-severity vulnerability—classified as problematic—was discovered in the Sourcecodester Simple Cashiering System, a open-source PHP platform popular for
CVE-2022-35740 Semicolon in a URL can be used to bypass access control and get sensitive information.
Through a combination of the above-mentioned issues, it is possible to construct dotCMS URIs that access arbitrary files. In dotCMS 5.3.8.12,
CVE-2022-43074 AyaCMS v3.1.2 had an arbitrary file upload vulnerability via the /admin/fst_upload.inc.php component.
An attacker can upload a PHP file via the component /admin/fst_upload.inc.php and then upload a file with a malicious code or
CVE-2022-44087 - How a File Upload Vulnerability in ESPCMS P8.21120101 Allows Remote Code Execution (RCE)
---
Introduction
In late 2022, a serious vulnerability (CVE-2022-44087) was discovered in ESPCMS P8.21120101, a popular content management system widely used for building
CVE-2022-39036 - RCE via Unfiltered File Upload in Agentflow BPM – A Simple Breakdown
Agentflow BPM is a workflow and business process management platform used in many organizations to automate their business processes. While it offers useful features, a
Episode
00:00:00
00:00:00