CVE-2022-39051 An attacker might be able to execute malicious Perl code in Template by having the admin install an unverified 3rd party package.
On a web server, where the Template is being used. The Template toolkit implementation of Perl is vulnerable to XSS attacks because it is implemented
CVE-2022-36636 The Garage Management System v1.0 SQL injection vulnerability was found at /print.php.
An attacker can inject SQL queries, run arbitrary PHP code, or obtain sensitive information by using the id parameter as an access token. The updated
CVE-2022-36582 An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code.
This is a file upload vulnerability and a user with file upload privileges can upload malicious files or corrupt files via the component /php_action/
CVE-2022-36689 The Stock Management System v1.0 had a SQL injection vulnerability in the month parameter.
Depending on the parameters used, hackers can manipulate the SQL query to dump data or create new databases. Another potential threat comes from insecure file
CVE-2022-32548 An issue was found on certain DrayTek Vigor routers before July 2022, such as the Vigor3910 4.3.1.1
An attacker can access or modify the aa or ab field to execute arbitrary code or cause a denial of service condition. When running the
Episode
00:00:00
00:00:00