RSS   Vulnerabilities for ' auditor website project'   RSS

2019-06-06
 
CVE-2019-7553

CWE-79
 

 
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.

 
2019-03-21
 
CVE-2018-20638

CWE-22
 

 
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.

 
 
CVE-2018-20637

CWE-119
 

 
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.

 
 
CVE-2018-20636

CWE-74
 

 
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.

 
2018-08-10
 
CVE-2018-15186

CWE-352
 

 
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.

 


Copyright 2024, cxsecurity.com

 

Back to Top