PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload:[CVE-2019-9605]

Vulnerability Description=> Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. ⇣ ⇣ ⇣ ⇣ How to... Continue Reading →

PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions:[CVE-2019-9604]

Vulnerability Description=> Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated. CSRF attacks specifically target state-changing requests, not theft of data, since the attacker has no way to see the response to the forged request. ↓ ↓ ↓ ↓... Continue Reading →

PHP-Script-Mall Personal Video Collection Script has Stored XSS in edit my Profile:[CVE-2019-9606]

Vulnerability Description => Cross-site scripting is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. ↑ ↑ ↑ How to Exploit... Continue Reading →

PHP Scripts Mall Custom T-Shirt Ecommerce Script has Parameter Tampering: [CVE-2019-9065]

Vulnerability Description => Parameter tampering is a form of Web-based attack in which certain parameters in the Uniform Resource Locator (URL) or Web page form field data entered by a user are changed without that user's authorization. Parameter tampering can result in product price manipulation. ↓ ↓ ↓ ↓ How to Exploit: ↓ ↓ ↓... Continue Reading →

PHP Scripts Mall Auction website script has Parameter Tampering: [CVE-2019-9063]

Vulnerability Description => Parameter tampering is a form of Web-based attack in which certain parameters in the Uniform Resource Locator (URL) or Web page form field data entered by a user are changed without that user's authorization. ↓ ↓ ↓ ↓ How to Exploit: ↓ ↓ ↓ ↓ 1. Go to Auction website script site (http://198.38.86.159/~prasanth/products/auction/)... Continue Reading →

PHP Scripts Mall Online Food Ordering Script has Cross-Site Request Forgery [CSRF] (PHP-Script-Mall):[CVE-2019-9062]

Vulnerability Description =>Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated. CSRF attacks specifically target state-changing requests, not theft of data since the attacker has no way to see the response to the forged request. How to exploit: Β ... Continue Reading →

Create a website or blog at WordPress.com

Up ↑

Design a site like this with WordPress.com
Get started