Advance Charity Management version 1.0 fails to set the secure flag on a session identifier.
b619f068851f84bcb5a73cd65452ce5e213bb46c52262a7a89d676950ff6659c
New MVC Shop version 1.0 suffers from remote SQL injection and missing attribute vulnerabilities.
c1b40aec9eb372ff9cd5a4cff29271a8df8d3fedfc4274f9e046058eaa80e539
Simple Customer Relationship Management CRM 2023 version 1.0 suffers from a remote SQL injection vulnerability.
285e8f6ae7ee9b90299b635cefdb4e7b115a2a1bf605db59f2801bc204f4e67e
2023 Online Course Registration version 1.0 suffers from a remote SQL Injection vulnerability that allows for authentication bypass.
97f89701c16c65008c586edfec5db4bfb42238c1ce697dfcbcc4be61071ce5d1
SEO Friendly Blog CMS version 1.0 suffers from a cross site scripting vulnerability.
e7b2aad9547591ccd71dc0ad3403b995793d10a7ef328925d3931ec0f6ff3cfd
GaanaGawaana Music Platform PHP Script version 1.0 suffers from cross site scripting and remote SQL injection vulnerabilities.
a82fb377371d1856a3f37cb5f375bdcdf4cec2a963adf0fc1fe40ca4153275e7
Textpattern version 4.8.8 logs the session token in a GET request where it may end up getting disclosed in logs or via a referer.
1ae8e0b552a4239f94e3a47bd60d1a40de5024ed400567419bb925ce5c2c66e0
Found Information System version 1.0 suffers from a remote SQL injection vulnerability.
9724732a654c4f2a42eafffec1fcd360cbfbd5be6629bb93ad92d91c5a47e054
AC Repair and Services version 1.0 suffers from a remote SQL injection vulnerability.
61ca067f3204dd60a28c5875c4c022cd31be78dd0d902d8f14cace50a68cc7d0
Old Age Home Management version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
6dbc0dac3bea894598dae10e5fce781c47ae87adbd89ddb496e7eb7cfc60c6a7
Microsoft Word appears to suffer from a remote code execution vulnerability when a user load a malicious file that reaches out to an attacker-controller server to get a hostile payload.
8ab600383b2980700b22b249418126bff6776fde4672ab8d2e1bbd8b3c50a7f2
Bludit versions 4.0.0-rc-2 and below suffer from an account takeover vulnerability due to an API key that can be abused to change the administrative password.
b70a284eeef12f45a9dc90cb28aaa83c01528151784f63f6980063c4811e257b
Microsoft Excel 365 MSO version 2302 build 16.0.16130.20186 64-bit suffers from a remote code execution vulnerability.
7c0643e760c2881c5a10ee8fb43171dfdd4b285f89952e06a6afdd7f15ff26f7
Microsoft Excel suffers from a spoofing vulnerability.
fa96d49859fc520f5cae2aff82756e1413ab3b90abbc5c84227e6a7ba5d34e63
bgERP version 22.31 suffers from a cross site scripting vulnerability.
fd20c29b02648c16215d048713c1fd5990682e789da718fb627ac88e64ab38df
Online Pizza Ordering version 1.0 suffers from a remote shell upload vulnerability.
61eb59acfd42c490af5b99991ace3533524b05c94b52f91de19087bd4542f2e7
AimOne Video Converter version 2.04 Build 103 suffers from a buffer overflow vulnerability that can cause a denial of service condition.
f4212c7bfd6ea0458d878e8fb94d4d66e64d4ba9f95fa0767acb1c92728e7f82
Online Pizza Ordering version 1.0 suffers from a remote SQL injection vulnerability.
469baff57259c3edfd5b9dc9e8bb4a1d8c40b8043d5480830f7ddc095f662638
rukovoditel version 3.2.1 suffers from a cross site scripting vulnerability.
898fcd6c42cf09cbd7ec5b6dc7da4c9a70126592c5acdb55261bfd7df9acfbaf
Beauty Salon version 1.0 suffers from a remote shell upload vulnerability.
83176cdbc6fac7bfcb64ea33d5b87412f89dd2c6fd208487f141a3594ec380e1
Lavalite version 9.0.0 suffers from a path traversal vulnerability.
d6085d1df4bbceda7849d49a14e340d1311171cc8e2f1b42c855dce50beb5675
Yoga Class Registration version 1.0 suffers from a remote SQL injection vulnerability.
e23511618b39cf967c8f37bb5757342f14d1f845146fa462ffd314f67403a96c
Purchase Order Management version 1.0 suffers a remote shell upload vulnerability. Flow details to achieve this are shown in the video link provided.
ebd87a2284147cd2df2e918dac7d56fd2fe8ef6e6817d1b763329b3720bb9d2a
Purchase Order Management version 1.0 appears to suffer from a cross site scripting vulnerability due to printing errors with a malicious password payload.
f1221013e8f2beac1700049c1a812303b165d11bb1c7cdd1db59c605ed5b50fb
Purchase Order Management version 1.0 suffers from a remote SQL injection vulnerability.
ffb44955bde18d06f61a43ace71d39f2ac737a3eb8396fe07643a49105c82640