PHP version 7.3.15-3 suffers from a PHP_SESSION_UPLOAD_PROGRESS session data injection vulnerability.
>> AUTHOR: deepcore
https://kangplu.go.th/krz.html notified by Mr.Kro0oz.305
https://bantan.go.th/krz.html notified by Mr.Kro0oz.305
https://samrong.go.th/krz.html notified by Mr.Kro0oz.305
https://khamtalayso.go.th/krz.html notified by Mr.Kro0oz.305
https://nonyor.go.th/krz.html notified by Mr.Kro0oz.305
https://naimeung.go.th/krz.html notified by Mr.Kro0oz.305
Event Registration System with QR Code 1.0 – Authentication Bypass & RCE
Denver Smart Wifi Camera SHC-150 – ‘Telnet’ Remote Code Execution (RCE)
TripSpark VEO Transportation – Blind SQL Injection