A vulnerability classified as critical was found in CARE2X. This vulnerability affects unknown code of the file inc_currency_set.php. The manipulation of the argument root_path leads to improper privilege management.
This vulnerability was named CVE-2007-1458. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal.
This vulnerability was named CVE-2025-6866. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in AlstraSoft Video Share Enterprise 4.0. Affected by this vulnerability is an unknown functionality of the file myajaxphp.php. The manipulation of the argument config[BASE_DIR] leads to file inclusion.
This vulnerability is known as CVE-2006-4443. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Kneuro LittleSite.php 0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ls.php. The manipulation of the argument File leads to path traversal.
This vulnerability is known as CVE-2009-3542. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in YourFreeWorld Stylish Text Ads Script. This affects an unknown part of the file trl.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-3754. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in Mitsubishi-automation Mitsubishi MX Component 3. This issue affects some unknown processing in the library ActUWzd.dll of the component ActiveX Control. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2013-3075. The attack may be initiated remotely. Furthermore, there is an exploit available.
Chinese Surveillance Firm Faces Canada National Security Ban Chinese video surveillance manufacturer Hikvision must close operations in Canada, a government official said Friday, citing national security concerns. The ban is the latest in a string of Western prohibitions against equipment made by partially state-owned Hangzhou Hikvision Digital Technology.
A vulnerability was found in Aspsiteware JobPost 1.0. It has been rated as critical. This issue affects some unknown processing of the file type.asp. The manipulation of the argument iType leads to sql injection.
The identification of this vulnerability is CVE-2010-1727. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Social Factory 3.8.3 on Joomla. This vulnerability affects unknown code. The manipulation of the argument radius[lat]/radius[lng]/radius[radius] as part of Parameter leads to sql injection.
This vulnerability was named CVE-2018-17385. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as problematic has been found in AlstraSoft Template Seller. This affects an unknown part of the file fullview.php. The manipulation of the argument tempid leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2006-0222. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in Mitsubishielectric MC-WorX Suite 8.02. This issue affects some unknown processing in the library IcoLaunch.dll of the component ActiveX Control. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2013-2817. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-6865. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in YaBB SE up to 1.5.3. Affected by this issue is some unknown functionality of the file SSI.php. The manipulation of the argument ID_MEMBER leads to sql injection.
This vulnerability is handled as CVE-2004-2754. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in pterodactyl panel up to 1.11.10. This affects an unknown part of the file /locales/locale.json. The manipulation of the argument locale/namespace leads to code injection.
This vulnerability is uniquely identified as CVE-2025-49132. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in DataEase. It has been classified as problematic. This affects an unknown part. The manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2024-57707. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability was found in PHPGurukul Land Record System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /landrecordsys/admin/dashboard.php of the component GET Request Parameter Handler. The manipulation of the argument Cookie leads to os command injection.
The identification of this vulnerability is CVE-2024-57687. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /landrecordsys/admin/contactus.php. The manipulation of the argument pagetitle leads to cross site scripting.
This vulnerability is known as CVE-2024-57686. The attack can be launched remotely. There is no exploit available.