Savsoft Quiz 5 – ‘field_title’ Stored Cross-Site Scripting
>> ARCHIVE: 2020-12
Savsoft Quiz 5 – ‘field_title’ Stored Cross-Site Scripting
Chromium 83 – Full CSP Bypass
Testa Online Test Management System 3.4.7 – ‘q’ SQL Injection
Phpscript-sgh 0.1.0 – Time Based Blind SQL Injection
MiniCMS 1.10 – ‘content box’ Stored XSS
Composr CMS 10.0.34 – ‘banners’ Persistent Cross Site Scripting
IDT PC Audio 1.0.6499.0 – ‘STacSV’ Unquoted Service Path
WordPress Plugin Canto 1.3.0 – Blind SSRF (Unauthenticated)
IDT PC Audio version 1.0.6433.0 suffer from an unquoted service path vulnerability.
WebDamn User Registration and Login System with User Panel suffers from a remote SQL injection vulnerability that allows for authentication bypass.