eddietcc/CVEnotes

eddietcc/CVEnotes

Releases0
Stars24

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.

4.3 MEDIUM

_includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.

4.9 MEDIUM

MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.

7.5 HIGH

MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.

7.5 HIGH

An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.

5.5 MEDIUM

In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.

4.3 MEDIUM

PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.

6.5 MEDIUM

An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.