RiteCMS version 3.1.0 and below suffers from a remote code execution in admin panel. An authenticated attacker can upload a php file and bypass the .htacess configuration that deny execution of .php files in media and files directory by default. There are 4 ways of bypassing the current file upload protection to achieve remote code execution.
The WordPress Plugin Picture Gallery 1.4.2 is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by injecting malicious JavaScript code into the 'Edit Content URL' input field in the admin panel. When the code is triggered, it executes in the context of the affected website, allowing the attacker to steal sensitive information or perform unauthorized actions on behalf of the user.
PEEL Shopping is an eCommerce shopping cart application in PHP / MySQL which works on any hosting. Public user/guest (unauthenticated) can inject malicious SQL query in order to affect the execution of predefined SQL commands via the "id" parameter on the "/peel-shopping_9_4_0/achat/produit_details.php?id=[SQLi]" endpoint. Upon successful of SQL injection attack, attacker can read sensitive data from the database or modify database data.
The Church Management System 1.0 is vulnerable to multiple stored cross-site scripting (XSS) attacks. An attacker can inject malicious code into the 'amount' and 'trcode' parameters, which are not properly sanitized, leading to the execution of arbitrary JavaScript code in the context of the user's browser.
The Cotonti Siena 0.9.19 application is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by entering a malicious payload in the 'maintitle' parameter in the Configuration tab of the Admin Panel. When the payload is saved and the home page is accessed, the XSS attack is triggered, allowing the execution of arbitrary JavaScript code.
This plugin allows admins to create and download database backups. A CSRF can create DB backups stored publicly in the uploads directory.
This exploit allows an attacker to execute arbitrary JavaScript code in the context of a user's browser by storing malicious script in the 'Comment' field of the restaurant reservation form.
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
A Reflected Cross-site scripting (XSS) vulnerability in Jenzabar v9.2.0 through 9.2.2. Attacker could inject web script or HTML via the query parameter (aka the Search Field). To exploit the vulnerability, someone must click the link.
The Openlitespeed WebServer version 1.7.8 is vulnerable to command injection. An attacker with authenticated access can inject a payload in the 'Command' value of the 'External App' configuration, leading to arbitrary command execution with the privileges of the web server. This can allow an attacker to take control of the affected system.