Vulnerabilities
REQUEST['src'] is passed directly into file_get_contents function.
1 MIN READ
Vulnerabilities
REQUEST['src'] is passed directly into file_get_contents function.
1 MIN READ
Vulnerabilities
$_GET['gpid'] is not escaped.
1 MIN READ
Vulnerabilities
_form_makercfm() is accessible for every registered user.
1 MIN READ
Vulnerabilities
$_GET['searchll'] is not escaped.
1 MIN READ
Vulnerabilities
$_GET['walbum'] is not escaped.
1 MIN READ
Vulnerabilities
_rednao_smart_forms_save_formvalues function is accessible for everyone through admin-ajax.php
2 MIN READ
Vulnerabilities
$_REQUEST['update_message'] is not escaped.
1 MIN READ
Vulnerabilities
Datas from checkboxes are not escaped and validated when added to database.
1 MIN READ
From 0 to pentesting hero
It may be found on every website that allows for exporting data to CSV format. But how the text format can be used for the attack?
27-03-2019
2 MIN READ