CVE-2020-28441
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will…
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will…
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. Zafiyet ile ilgili Genel Bilgi, Etki ve Çözümleri için Devamını Oku…
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function. Zafiyet ile ilgili Genel…
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. Zafiyet ile ilgili Genel Bilgi, Etki ve Çözümleri için Devamını Oku Kaynak: National…
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath) Zafiyet ile ilgili…
All versions of package git-archive are vulnerable to Command Injection via the exports function. Zafiyet ile ilgili Genel Bilgi, Etki ve Çözümleri için Devamını Oku…
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action,…
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading…
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a…
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to…