Skip to content

TechMedia

Header Image
Archive

Month: April 2023

2328 Posts

Featured

Posted byWpmaster
大規模対戦ACT『Warlander』PS5/XSX版最新情報を公開―新コンテンツ追加やゲーム改善をリリースに向けて開発中
Posted byWpmaster
サウナブームが到来!!「ととのう」を提供するべく新サウナ施設や様々なサウナグッズが登場 (マイライフニュース)
Posted byWpmaster
吉野家HDの24年2月期、営業益34%増 12年ぶり水準 (日本経済新聞)
Posted byWpmaster
【フォト】大規模反攻、夏にずれ込む可能性 ウクライナ首相 (産経新聞)

[microweber/microweber] Microweber vulnerable to command injection

  • Posted inMODERATE
  • Posted byWpmaster
  • 04/06/202304/07/2023

microweber/microweber prior to 1.3.3 is vulnerable to command injection in the “first name” field. This allows for server-side template injection, which can lead to arbitrary code execution.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1877
ht…

[microweber/microweber] Microweber vulnerable to stored cross-site scripting (XSS) via X-Forwarded-For header

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

microweber/microweber prior to 1.3.3 is vulnerable to stored cross-site scripting (XSS) via the X-Forwarded-For header. This was fixed in version 1.3.3.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1881
https://github.com/microweber/microweber…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameter

  • Posted inMODERATE
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the category field name parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1885…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to DOM cross-site scripting (XSS) via configuration privacy note URL parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to DOM cross-site scripting (XSS) because it fails to sanitize user input in the configuration privacy note URL parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via HTML export

  • Posted inMODERATE
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the FAQ site while generating an HTML Export. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CV…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter

  • Posted inMODERATE
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the updatecategory parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1879
http…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via artlang parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the artlang parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1880
https://git…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via adminlog

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the adminlog. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-1878
https://github.com/t…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameter

  • Posted inHIGH
  • Posted byWpmaster
  • 04/06/202304/12/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input in the FAQ comment username parameter. This has been fixed in 3.1.12.
References

https://nvd.nist.gov/vuln/detail/CVE-2023-175…

[thorsten/phpmyfaq] thorsten/phpmyfaq vulnerable to improper access control

  • Posted inMODERATE
  • Posted byWpmaster
  • 04/06/202304/07/2023

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to improper access control when FAQ News is marked as inactive in settings and have comments enabled, allowing comments to be posted on inactive FAQs. This has been fixed in 3.1.12.
References

https://nv…

Posts navigation

Previous Posts 1 … 217 218 219 220 221 … 233 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close