An SQL injection vulnerability exists in Web Ofisi Firma Rehberi 1, which allows an attacker to execute arbitrary SQL commands via the 'il', 'kelime', and 'kat' parameters in the 'firmalar.html' page.
Web Ofisi Emlak 2 is prone to a SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to access or modify data in the back-end database, compromise the system, execute operating system commands, or exploit other vulnerabilities.
Web Ofisi Platinum E-Ticaret 5 is prone to an SQL injection vulnerability due to improper sanitization of user-supplied input to the 'q' parameter in the 'arama' and 'ajax/productsFilterSearch' scripts. An attacker can exploit this vulnerability to inject arbitrary SQL commands and gain access to sensitive information in the back-end database.
Web Ofisi E-Ticaret 3 is prone to a SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to access or modify data in the back-end database, compromise the application, access or elevate privileges, or execute arbitrary commands on the operating system.
An attacker can execute arbitrary code on the vulnerable system by sending a crafted HTTP request to the vulnerable application. This is due to the application not properly sanitizing user-supplied input before using it in a dynamic function call. This vulnerability affects fuel CMS version 1.4.1 and earlier.
When called for PTRACE_TRACEME, ptrace_link() would obtain an RCU reference to the parent's objective credentials, then give that pointer to get_cred(). However, the object lifetime rules for things like struct cred do not permit unconditionally turning an RCU reference into a stable reference. PTRACE_TRACEME records the parent's credentials as if the parent was acting as the subject, but that's not the case. If a malicious unprivileged child uses PTRACE_TRACEME and the parent is privileged, and at a later point, the parent process becomes attacker-controlled (because it drops privileges and calls execve()), the attacker ends up with control over two processes with a privileged ptrace relationship, which can be abused to ptrace a suid binary and obtain root privileges.
A denial of service vulnerability exists in WinMPG iPod Convert 3.0 when a maliciously crafted 'User Name and User Code' is pasted into the 'Register' field, resulting in a crash.
There exists a privilege escalation vulnerability for Windows 10 builds prior to build 17763. Due to the AppXSvc's improper handling of hard links, a user can gain full privileges over a SYSTEM-owned file. The user can then utilize the new file to execute code as SYSTEM. This module employs a technique using the Diagnostics Hub Standard Collector Service (DiagHub) which was discovered by James Forshaw to load and execute a DLL as SYSTEM.
Microsoft Compiled HTML Help is a Microsoft proprietary online help format, consisting of a collection of HTML pages, an index and other navigation tools. The files are compressed and deployed in a binary format with the extension .CHM, for Compiled HTML. The format is often used for software documentation. CHM is an extension for the Compiled HTML file format, most commonly used by Microsoft's HTML-based help program. CHM Files are usually created using Microsofts "HTML Help Workshop" program. However, it is possible to bypass using this program and create them easily by simply adding double .chm extension to the file ".chm.chm". Compiled HTML Help "hh.exe" will then respect and open it processing any JS/HTML/XML inside etc. Compiled HTML Help is also vulnerable to XML External Entity attacks allowing remote attackers to steal and exfiltrate local system files.
The server response different message between login with valid and invalid user. This allows attackers to check whether a username is valid by reading the HTTP response.