Vulnerabilities
WP Photo Album Plus 5.4.17 Reflected XSS
$_GET['walbum'] is not escaped.
06-11-2014
1 MIN READ
Vulnerabilities
$_GET['walbum'] is not escaped.
1 MIN READ
Vulnerabilities
_rednao_smart_forms_save_formvalues function is accessible for everyone through admin-ajax.php
2 MIN READ
Vulnerabilities
$_REQUEST['update_message'] is not escaped.
1 MIN READ
Vulnerabilities
Datas from checkboxes are not escaped and validated when added to database.
1 MIN READ
Vulnerabilities
**Ai1wm_Import_Controller
1 MIN READ
From 0 to pentesting hero
The functionality of file upload is a key place where we should pay special attention to. If the attacker successfully sends and executes a malicious file, the whole server may be taken over.
12-03-2019
3 MIN READ