Author: Angelo Barbosa

CVE-2024-10756 | PHPGurukul Online Shopping Portal 2.0 html_table.php scripts cross site scripting

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. The manipulation of the argument scripts leads to cross site scripting. This vulnerability is known as CVE-2024-10756. The attack can be launched remotely. Furthermore, there is an exploit...

Read More

CVE-2024-10755 | PHPGurukul Online Shopping Portal 2.0 empty_table.php scripts cross site scripting

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation of the argument scripts leads to cross site scripting. This vulnerability is traded as CVE-2024-10755. It is possible to launch the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2024-10754 | PHPGurukul Online Shopping Portal 2.0 dymanic_table.php scripts cross site scripting

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dymanic_table.php. The manipulation of the argument scripts leads to cross site scripting. The identification of this vulnerability is CVE-2024-10754. The attack may be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2024-10753 | PHPGurukul Online Shopping Portal 2.0 dom_data_two_headers.php scripts cross site scripting

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts leads to cross site scripting. This vulnerability was named CVE-2024-10753. The attack can be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2024-10752 | Codezips Pet Shop Management System 1.0 /productsadd.php id sql injection

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file /productsadd.php. The manipulation of the argument id leads to sql injection. This vulnerability is uniquely identified as CVE-2024-10752. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. The initial researcher advisory mentions contradicting file names to be...

Read More