<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Karma(In)Security</title>
    <link>https://karmainsecurity.com/</link>
    <description>Recent content on Karma(In)Security</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 07 Jun 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://karmainsecurity.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Riding The Time Machine: Journey Through An Old vBulletin PHP Object Injection</title>
      <link>https://karmainsecurity.com/riding-the-time-machine-old-vbulletin-php-object-injection/</link>
      <pubDate>Sat, 07 Jun 2025 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/riding-the-time-machine-old-vbulletin-php-object-injection/</guid>
      <description>Dust off your dial-up modem and fire up your favorite IRC client — today, we&amp;rsquo;re boarding a time machine straight into the golden era of web forums. About a decade ago, somewhere between the rise of jQuery and the fall of Flash, vBulletin 4.x was king. It powered countless online communities, from gaming clans to enterprise tech support boards. And like many kings of old, it had its share of dark secrets. In this blog post, we&amp;rsquo;ll be digging into a pretty esoteric PHP Object Injection vulnerability I recently spotted on certain vBulletin 4.x versions&amp;hellip;</description>
    </item>
    
    <item>
      <title>Don&#39;t Call That &#34;Protected&#34; Method: Dissecting an N-Day vBulletin RCE</title>
      <link>https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce/</link>
      <pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce/</guid>
      <description>vBulletin is one of the most widely used commercial forum solutions over the Internet, powering thousands of online communities ranging from niche hobbyist sites to large-scale tech forums. Developed primarily in PHP, it features a custom MVC-like framework and a proprietary API system designed to handle AJAX and mobile app interactions. Over the years, vBulletin has gained a reputation for both its ubiquity and its vulnerability surface — often becoming a prime target for web application exploits.</description>
    </item>
    
    <item>
      <title>Hacking Kerio Control via CVE-2024-52875: from CRLF Injection to 1-click RCE</title>
      <link>https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875/</link>
      <pubDate>Mon, 16 Dec 2024 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875/</guid>
      <description>Kerio Control, formerly known as Kerio WinRoute Firewall, is nowadays quite a popular firewall and Unified Threat Management (UTM) product owned and developed by GFI Software: according to Censys, at the moment there are around twenty thousands Kerio Control instances across the Internet! Kerio Control can be considered a network security solution that manages security services such as intrusion detection (IDS) and prevention (IPS), gateway antivirus, VPN, web content, application filtering, and endpoint security&amp;hellip;</description>
    </item>
    
    <item>
      <title>Zip Slip meets Artifactory: A Bug Bounty Story</title>
      <link>https://karmainsecurity.com/zip-slip-meets-artifactory-a-bug-bounty-story/</link>
      <pubDate>Sun, 23 Jun 2024 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/zip-slip-meets-artifactory-a-bug-bounty-story/</guid>
      <description>Artifactory, developed by JFrog, is an industry-leading software repository manager, a single solution for storing and managing all the artifacts, binaries, packages, files, containers, and components for use throughout the software supply chain. JFrog Artifactory serves as a central hub for DevOps, integrating with software development tools and processes.
In this blog post I&amp;rsquo;m going to tell a story about a Zip Slip vulnerability in Artifactory I reported to the JFrog private Bug Bounty Program in early 2021, a security bug for which I got a bounty of USD 5000$ and some cool swags!</description>
    </item>
    
    <item>
      <title>Exploiting an N-day vBulletin PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/exploiting-an-nday-vbulletin-php-object-injection/</link>
      <pubDate>Sat, 26 Nov 2022 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/exploiting-an-nday-vbulletin-php-object-injection/</guid>
      <description>vBulletin is one of the most popular proprietary forum solutions over the Internet. It is used by some major websites, and according to the BuildWith website, vBulletin currently ranks at the second place on the Forum Software Usage Distribution in the Top 1 Million Sites, with over 2.000 websites using it among the “top 1 million”. vBulletin is also known for some famous 0-day Remote Code Execution (RCE) vulnerabilities that led to significant data breaches in 2019 and 2020.</description>
    </item>
    
    <item>
      <title>ImpressCMS: from unauthenticated SQL Injection to RCE</title>
      <link>https://karmainsecurity.com/impresscms-from-unauthenticated-sqli-to-rce/</link>
      <pubDate>Wed, 23 Mar 2022 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/impresscms-from-unauthenticated-sqli-to-rce/</guid>
      <description>According to the official website ImpressCMS is an open source Content Management System (CMS) designed to easily and securely manage multilingual web sites. With this tool maintaining the content of a website becomes as easy as writing a word document. ImpressCMS is the ideal tool for a wide range of users: from business to community users, from large enterprises to people who want a simple, easy to use blogging tool. ImpressCMS is a powerful system that gets outstanding results and it&amp;rsquo;s free!</description>
    </item>
    
    <item>
      <title>Tales of SugarCRM Security Horrors</title>
      <link>https://karmainsecurity.com/tales-of-sugarcrm-security-horrors/</link>
      <pubDate>Sun, 23 Apr 2017 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/tales-of-sugarcrm-security-horrors/</guid>
      <description>SugarCRM is a pretty popular Customer Relationship Management (CRM) application written in PHP code. It was born in 2004 as an open source project hosted on SourceForge, a development repository for free software. By June of the same year, the rapid success of the project allowed the original developers to found SugarCRM Inc. and raise $2 million in venture capital. A month later, on July 3, Sugar Open Source version 1.0 was released. In October 2004, more than 35.000 people had downloaded the software which had been upgraded to version 2.0, and it was named “Project of the Month” on SourceForge.</description>
    </item>
    
    <item>
      <title>Hacking Magento eCommerce For Fun And 17.000 USD</title>
      <link>https://karmainsecurity.com/hacking-magento-ecommerce-for-fun-and-17000-usd/</link>
      <pubDate>Thu, 03 Mar 2016 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/hacking-magento-ecommerce-for-fun-and-17000-usd/</guid>
      <description>Magento, which was acquired by Ebay Inc back in 2011, is one of the most popular e-commerce platforms written in PHP. There is an interesting bug bounty program in place that offers bounties of up to 10,000$ for Information Disclosure and Remote Code Execution vulnerabilities. In November 2014, I decided to give it a try, so I started looking for security bugs in Magento CE, and almost immediately I discovered a PHP Object Injection vulnerability which (un)fortunately requires administrator privileges in order to be exploited.</description>
    </item>
    
    <item>
      <title>My adventure at JoomlaDay Italy 2013 (and my thoughts on the JSST)</title>
      <link>https://karmainsecurity.com/my-adventure-at-joomladay-italy-2013-and-my-thoughts-on-the-jsst/</link>
      <pubDate>Sun, 12 Oct 2014 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/my-adventure-at-joomladay-italy-2013-and-my-thoughts-on-the-jsst/</guid>
      <description>Just a year ago I had the pleasure to talk about the PHP Object Injection vulnerabilities I discovered in Joomla at the JoomlaDay Italy 2013 held in Naples, one of the most beautiful cities I have ever seen. Today I would like to share with you my experience at that day and some further details about the disclosure process I had with the Joomla! Security Strike Team (JSST).Before that, I would like to take the opportunity to say thank you to Alessandro Rossi (AlexRed), one of the Italian JoomlaDay’s organizers, and most of all the guy who personally invited me on the JoomlaDay’s stage, giving me the chance to show that the vulnerabilities I discovered are actually a bit more critical compared to what the JSST has stated in its bulletins.</description>
    </item>
    
    <item>
      <title>Exploiting CVE-2014-1691: Horde Framework PHP Object Injection</title>
      <link>https://karmainsecurity.com/exploiting-cve-2014-1691-horde-framework-php-object-injection/</link>
      <pubDate>Mon, 17 Feb 2014 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/exploiting-cve-2014-1691-horde-framework-php-object-injection/</guid>
      <description>Welcome to my third blog post ever, the first in this new year, but still talking about an old friend of mine. Yes, 2014 is here, however the topic is always the same: PHP Object Injection! Perhaps those few people who read my blog are wondering if I will ever write about something else, or whether this is going to be a monothematic blog… Well, who knows?! It could be, or maybe not, but the point is that right now I’m really in love with this kind of vulnerabilities, and today I would like to share with you what in my view is an interesting story about a PHP Object Injection vulnerability which affected the Horde Framework.</description>
    </item>
    
    <item>
      <title>Yet Another Joomla PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/remember-the-joomla-php-object-injection-vulnerability/</link>
      <pubDate>Mon, 06 May 2013 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/remember-the-joomla-php-object-injection-vulnerability/</guid>
      <description>Last week I have disclosed KIS-2013-04, another PHP Object Injection vulnerability which affects the Joomla CMS. I had initially reported this vulnerability to the Joomla Security Strike Team in December last year, within an e-mail reply about the KIS-2013-03 vulnerability: “Furthermore, I would suggest you to investigate other potentially vulnerable unserialize() calls, for example the plgSystemRemember::onAfterInitialise() method uses the unserialize() function with user input passed through cookies, but I’m not sure it may be exploitable, due to the encryption system”.</description>
    </item>
    
    <item>
      <title>Analysis of the Joomla PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/analysis-of-the-joomla-php-object-injection-vulnerability/</link>
      <pubDate>Wed, 27 Feb 2013 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/analysis-of-the-joomla-php-object-injection-vulnerability/</guid>
      <description>Today I have disclosed KIS-2013-03, a PHP Object Injection vulnerability which affects the Joomla CMS. I have reported this vulnerability to the Joomla Security Strike Team only some months ago, but to be honest I have noticed that vulnerable unserialize() call a long time before. The only one reason why I have not notified them before is because I thought that it wasn’t exploitable: I had not noticed any useful magic method which could be abused to conduct malicious attacks, so I have come to the conclusion that it wasn’t an actual security vulnerability.</description>
    </item>
    
    <item>
      <title>1C-Bitrix &lt;= 25.100.500 (Translate Module) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-08/</guid>
      <description>• Software Link: https://www.1c-bitrix.ru
• Affected Versions: Version 25.100.500 and prior versions.
• Vulnerability Description: The vulnerability is located within the &amp;ldquo;Translate Module&amp;rdquo;, which allows users to upload and extract archive files into a temporary directory. However, the application fails to properly verify the contents of these archives before extracting them. This can be exploited by malicious users to upload and execute arbitrary PHP code by including a PHP file along with a specially crafted .</description>
    </item>
    
    <item>
      <title>About</title>
      <link>https://karmainsecurity.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/about/</guid>
      <description>My name is Egidio Romano and I’m also known as &amp;quot;EgiX&amp;quot;, which is the nickname I chose when I was fifteen. I got a BS in Computer Science at the University of Catania, Italy. I am passionate about computer security, and addicted to web application security.
After gaining solid experience in the IT security industry, I decided to bet on myself and go solo. So, I currently work as a freelance IT security consultant, mainly focusing on web application security code review, penetration testing, and 0-day vulnerability research.</description>
    </item>
    
    <item>
      <title>Achievo &lt;= 1.3.2 (FCKEditor) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-20/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-20/</guid>
      <description>Description: Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
References:  CVE-2008-2742 BID-29621 EDB-5770  Disclosure Date: June 9, 2008</description>
    </item>
    
    <item>
      <title>aidiCMS v3.55 (ajax_create_folder.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-62/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-62/</guid>
      <description>Description: Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References:  CVE-2011-4825 BID-50523 EDB-18085  Disclosure Date: November 5, 2011</description>
    </item>
    
    <item>
      <title>Ajax File and Image Manager v1.0 PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-61/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-61/</guid>
      <description>Description: Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References:  CVE-2011-4825 BID-50523 EDB-18075  Disclosure Date: November 4, 2011</description>
    </item>
    
    <item>
      <title>appRain CMF &lt;= 0.1.5 (uploadify.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-77/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-77/</guid>
      <description>Description: appRain contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the application uses the uploadify.php script, which does not properly verify or sanitize user-uploaded files.
References:  CVE-2012-1153 BID-51576 EDB-18392  Disclosure Date: January 19, 2012</description>
    </item>
    
    <item>
      <title>ATutor &lt;= 2.2 (confirm.php) Session Variable Overloading Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-06/</guid>
      <description>• Software Link: http://www.atutor.ca
• Affected Versions: Version 2.2 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /confirm.php script:
140if (isset($_REQUEST[&amp;#39;auto_login&amp;#39;])) 141{ 142 143 $sql = &amp;#34;SELECT M.member_id, M.login, M.preferences, M.language FROM %smembers M WHERE M.member_id=%d&amp;#34;; 144 $row = queryDB($sql, array(TABLE_PREFIX, $_REQUEST[&amp;#34;member_id&amp;#34;]), TRUE); 145 146 if ($row[&amp;#39;member_id&amp;#39;] != &amp;#39;&amp;#39;) 147 { 148 $_SESSION[&amp;#39;valid_user&amp;#39;] = true; 149 $_SESSION[&amp;#39;member_id&amp;#39;] = $_REQUEST[&amp;#34;member_id&amp;#34;]; 150 $_SESSION[&amp;#39;course_id&amp;#39;] = 0; 151 $_SESSION[&amp;#39;login&amp;#39;] = $row[login]; This script is intended to be used for the account confirmation.</description>
    </item>
    
    <item>
      <title>ATutor &lt;= 2.2 (Custom Course Icon) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-05/</guid>
      <description>• Software Link: http://www.atutor.ca
• Affected Versions: Version 2.2 and prior versions.
• Vulnerability Description: User input passed through the &amp;ldquo;customicon&amp;rdquo; parameter when creating a new course is not properly sanitized before being uploaded into the /content/ directory. This could be exploited to upload and execute arbitrary PHP code. Successful exploitation of this vulnerability should require an account with permissions to create new courses, however it could be exploited in conjunction with KIS-2015-06 in order to bypass the authentication mechanism.</description>
    </item>
    
    <item>
      <title>ATutor &lt;= 2.2 (edit_marks.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-08/</guid>
      <description>• Software Link: http://www.atutor.ca
• Affected Versions: Version 2.2 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /mods/_standard/gradebook/edit_marks.php script:
54if (isset($_GET[&amp;#39;asc&amp;#39;])) 55{ 56 $order = &amp;#39;asc&amp;#39;; 57 $order_col = $addslashes($_GET[&amp;#39;asc&amp;#39;]); 58} 59else if (isset($_GET[&amp;#39;desc&amp;#39;])) { 60 $order = &amp;#39;desc&amp;#39;; 61 $order_col = $addslashes($_GET[&amp;#39;desc&amp;#39;]); 185if ((isset($_GET[&amp;#34;asc&amp;#34;]) || isset($_GET[&amp;#34;desc&amp;#34;])) &amp;amp;&amp;amp; $order_col &amp;lt;&amp;gt; &amp;#34;name&amp;#34;) 186{ 187 $sort = &amp;#39;$grades[&amp;#39;.$order_col.&amp;#39;], SORT_&amp;#39;.strtoupper($order).&amp;#39;, $selected_students, SORT_&amp;#39;.strtoupper($order); 188 189 foreach($selected_tests as $test) 190 { 191 if ($test[&amp;#34;gradebook_test_id&amp;#34;] &amp;lt;&amp;gt; $order_col) 192 $sort .</description>
    </item>
    
    <item>
      <title>ATutor &lt;= 2.2 (popuphelp.php) Reflected Cross-Site Scripting Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-07/</guid>
      <description>• Software Link: http://www.atutor.ca
• Affected Versions: Version 2.2 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /popuphelp.php script:
26if ($_GET[&amp;#39;h&amp;#39;]) { 27 $h = $_GET[&amp;#39;h&amp;#39;]; 28 29 if (is_string($_GET[&amp;#39;h&amp;#39;])) { // just a AT_HELP code with no prefix 30 $msg-&amp;gt;printHelps($h); User input passed through the &amp;ldquo;h&amp;rdquo; GET parameter is not properly sanitized before being passed to the Message::printHelps() method at line 30. This can be exploited to carry out Reflected Cross-Site Scripting (XSS) attacks.</description>
    </item>
    
    <item>
      <title>Bitrix24 &lt;= 25.100.300 (Translate Module) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-07/</guid>
      <description>• Software Link: https://www.bitrix24.com
• Affected Versions: Version 25.100.300 and prior versions.
• Vulnerability Description: The vulnerability is located within the &amp;ldquo;Translate Module&amp;rdquo;, which allows users to upload and extract archive files into a temporary directory. However, the application fails to properly verify the contents of these archives before extracting them. This can be exploited by malicious users to upload and execute arbitrary PHP code by including a PHP file along with a specially crafted .</description>
    </item>
    
    <item>
      <title>Cacti &lt;= 1.2.26 (import.php) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2024-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-04/</guid>
      <description>• Software Link: https://cacti.net
• Affected Versions: Version 1.2.26 and prior versions.
• Vulnerability Description: The vulnerability is located within the import_package() function defined into the /lib/import.php script. This function blindly trusts the filename and file content provided within the uploaded XML data, and writes such files into the Cacti base path (or even outside, since Path Traversal sequences are not filtered). This can be exploited to write or overwrite arbitrary files on the web server, leading to execution of arbitrary PHP code or other security impacts.</description>
    </item>
    
    <item>
      <title>CakePHP &lt;= 3.2.0 &#34;_method&#34; CSRF Protection Bypass Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-01/</guid>
      <description>• Software Link: http://cakephp.org
• Affected Versions: Version 3.2.0 RC1 and prior 3.x versions.
Version 2.8.0 RC1 and prior 2.x versions.
• Vulnerability Description: CakePHP provides some built-in security features including CSRF and Form Tampering protection. Under certain circumstances it might be possible to bypass such security checks, since they are performed only when the HTTP request is e.g. POST or PUT. CakePHP&amp;quot;s Router class uses a number of different indicators to detect the HTTP method being used, like the &amp;quot;_method&amp;quot; POST parameter and the “X_HTTP_METHOD_OVERRIDE” and “REQUEST_METHOD” headers.</description>
    </item>
    
    <item>
      <title>CMS from Scratch &lt;= 1.1.3 (FCKEditor) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-19/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-19/</guid>
      <description>Description: CMS from Scratch contains a flaw that allows a remote user to execute arbitrary PHP code. The vulnerability is caused due to an error in the handling of file uploads in the cms/FCKeditor/editor/filemanager/connectors/php/upload.php script, when a file name has multiple file extensions. This can be exploited to upload malicious PHP scripts.
References:  BID-29431 EDB-5691  Disclosure Date: May 29, 2008</description>
    </item>
    
    <item>
      <title>CMS Made Simple &lt;= 1.2.2 (content_css.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-8/</guid>
      <description>Description: CMS Made Simple contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the &amp;lsquo;modules/TinyMCE/content_css.php&amp;rsquo; script not properly sanitizing user-supplied input to the &amp;lsquo;templateid&amp;rsquo; parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  CVE-2007-6656 BID-27074 EDB-4810  Disclosure Date: December 30, 2007</description>
    </item>
    
    <item>
      <title>CMS Made Simple &lt;= 1.2.4 Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-16/</guid>
      <description>Description: Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6) .php5, or (7) .jar, then accessing it via a direct request to the file in modules/FileManager/postlet/.
References:  CVE-2008-2267 BID-29170 EDB-5600  Disclosure Date: May 12, 2008</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 5.7.3.1 (Application::dispatch) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-10/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 5.7.3.1 and probably other versions.
• Vulnerability Description: The vulnerable code is located within the Application::dispatch() method:
326public function dispatch(Request $request) 327{ 328 if ($this-&amp;gt;installed) { 329 $response = $this-&amp;gt;getEarlyDispatchResponse(); 330 } 331 if (!isset($response)) { 332 $collection = Route::getList(); 333 $context = new \Symfony\Component\Routing\RequestContext(); 334 $context-&amp;gt;fromRequest($request); 335 $matcher = new UrlMatcher($collection, $context); 336 $path = rtrim($request-&amp;gt;getPathInfo(), &amp;#39;/&amp;#39;) . &amp;#39;/&amp;#39;; 337 try { 338 $request-&amp;gt;attributes-&amp;gt;add($matcher-&amp;gt;match($path)); 339 $matched = $matcher-&amp;gt;match($path); 340 $route = $collection-&amp;gt;get($matched[&amp;#39;_route&amp;#39;]); 341 Route::setRequest($request); 342 $response = Route::execute($route, $matched); The vulnerability exists because the path for the incoming request is retrieved using the Request::getPathInfo() method from the Symfony framework, which allows to specify the path for the request within some HTTP headers (like &amp;ldquo;X-Original-URL&amp;rdquo; and some others).</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 5.7.3.1 (sendmail) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-01/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 5.7.3.1 and probably other versions.
• Vulnerability Description: The vulnerable code is located in /concrete/controllers/single_page/dashboard/system/registration/open.php:
21switch ($this-&amp;gt;post(&amp;#39;registration_type&amp;#39;)) { 22 case &amp;#34;enabled&amp;#34;: 23 Config::save(&amp;#39;concrete.user.registration.enabled&amp;#39;, true); 24 Config::save(&amp;#39;concrete.user.registration.validate_email&amp;#39;, false); 25 Config::save(&amp;#39;concrete.user.registration.approval&amp;#39;, false); 26 Config::save(&amp;#39;concrete.user.registration.notification&amp;#39;, $this-&amp;gt;post(&amp;#39;register_notification&amp;#39;)); 27 Config::save( 28 &amp;#39;concrete.user.registration.notification_email&amp;#39;, 29 Loader::helper(&amp;#39;security&amp;#39;)-&amp;gt;sanitizeString( 30 $this-&amp;gt;post(&amp;#39;register_notification_email&amp;#39;))); 31 break; User input passed through the &amp;ldquo;register_notification_email&amp;rdquo; POST parameter is not properly sanitized before being stored into a configuration setting at lines 27-30 (the sanitizeString() method doesn’t check if it is a valid email address).</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 5.7.3.1 Multiple Cross-Site Request Forgeries Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2016-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-08/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 5.7.3.1 and probably other versions.
• Vulnerabilities Description: Concrete5 implements a Synchronizer Token Pattern in order to provide anti-CSRF capabilities. However, the application fails to properly use this feature in every block or dashboard page which makes a system state change, such as settings modification. As a result, the application is vulnerable to some Cross-Site Request Forgery (CSRF) attacks:
  File Manager – Delete: an attacker might force an authenticated user to delete files from the File Manager by tricking the victim into browsing to a specially crafted web page.</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 5.7.3.1 Multiple Reflected Cross-Site Scripting Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2015-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-02/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 5.7.3.1 and probably other versions.
• Vulnerabilities Description:  The vulnerable code is located in /concrete/views/panels/details/page/versions.php:  5&amp;lt;? foreach($_REQUEST[&amp;#39;cvID&amp;#39;] as $cvID) { 6$tabs[] = array(&amp;#39;view-version-&amp;#39; . $cvID, t(&amp;#39;Version %s&amp;#39;, $cvID), $checked); 7$checked = false; 8} 9print $ih-&amp;gt;tabs($tabs); 10foreach($_REQUEST[&amp;#39;cvID&amp;#39;] as $cvID) { ?&amp;gt; 11 12 &amp;lt;div id=&amp;#34;ccm-tab-content-view-version-&amp;lt;?=$cvID?&amp;gt;&amp;#34; style=&amp;#34;display: &amp;lt;?=$display?&amp;gt;; height: 100%&amp;#34;&amp;gt; 13 &amp;lt;iframe border=&amp;#34;0&amp;#34; id=&amp;#34;v&amp;lt;?=time()?&amp;gt;&amp;#34; frameborder=&amp;#34;0&amp;#34; height=&amp;#34;100%&amp;#34; width=&amp;#34;100%&amp;#34; src=&amp;#34;&amp;lt;?=REL_DIR_FILES_TOOLS_REQUIRED?&amp;gt;/pages/preview_version?cvID=&amp;lt;?=$cvID?&amp;gt;&amp;amp;amp;cID=&amp;lt;?=$_REQUEST[&amp;#39;cID&amp;#39;]?&amp;gt;&amp;#34; /&amp;gt; User input passed through the &amp;ldquo;cvID&amp;rdquo; and &amp;ldquo;cID&amp;rdquo; request parameters is not properly sanitized before being used to generate HTML output at lines 6 and 13.</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 5.7.3.1 Multiple Stored Cross-Site Scripting Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2016-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-09/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 5.7.3.1 and probably other versions.
• Vulnerabilities Description:  User input passed through the &amp;ldquo;uEmail&amp;rdquo; and &amp;ldquo;uDefaultLanguage&amp;rdquo; POST parameters when registering a new account is not properly sanitized before being used to generate HTML output. This can be exploited by unauthenticated attackers to permanently store arbitrary script code within the Users database table, which might be executed by an authenticated user while browsing to the users page.</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 5.7.4 (Access.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-03/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 5.7.3.1, 5.7.4, and probably other versions.
• Vulnerability Description: The vulnerable code is located in /concrete/src/Permission/Access/Access.php:
168protected function buildAssignmentFilterString($accessType, $filterEntities) 169{ 170 $peIDs = &amp;#39;&amp;#39;; 171 $filters = array(); 172 if (count($filterEntities) &amp;gt; 0) { 173 foreach ($filterEntities as $ent) { 174 $filters[] = $ent-&amp;gt;getAccessEntityID(); 175 } 176 $peIDs .= &amp;#39;and peID in (&amp;#39; . implode($filters, &amp;#39;,&amp;#39;) . &amp;#39;)&amp;#39;; 177 } 178 if ($accessType == 0) { 179 $accessType = &amp;#39;&amp;#39;; 180 } else { 181 $accessType = &amp;#39; and accessType = &amp;#39; .</description>
    </item>
    
    <item>
      <title>Concrete5 &lt;= 8.5.5 (Logging Settings) Phar Deserialization Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2021-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2021-05/</guid>
      <description>• Software Link: https://www.concrete5.org
• Affected Versions: Version 8.5.5 and prior versions.
• Vulnerability Description: The vulnerable code is located within the /concrete/controllers/single_page/dashboard/system/environment/logging.php script. Specifically, into the Logging::update_logging() method:
61public function update_logging() 62{ 63 $config = $this-&amp;gt;app-&amp;gt;make(&amp;#39;config&amp;#39;); 64 $request = $this-&amp;gt;request; 65 66 if (!$this-&amp;gt;token-&amp;gt;validate(&amp;#39;update_logging&amp;#39;)) { 67 return $this-&amp;gt;showError($this-&amp;gt;token-&amp;gt;getErrorMessage()); 68 } 69 70 // Load in variables from the request 71 $mode = (string) $request-&amp;gt;request-&amp;gt;get(&amp;#39;logging_mode&amp;#39;) === &amp;#39;advanced&amp;#39; ? &amp;#39;advanced&amp;#39; : &amp;#39;simple&amp;#39;; 72 $handler = $mode === &amp;#39;simple&amp;#39; ?</description>
    </item>
    
    <item>
      <title>Control Web Panel &lt;= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-09/</guid>
      <description>• Software Link: https://control-webpanel.com
• Affected Versions: Version 0.9.8.1208 and prior versions.
• Vulnerability Description: User input passed via the &amp;ldquo;key&amp;rdquo; GET parameter to /admin/index.php (when the &amp;ldquo;api&amp;rdquo; parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute arbitrary OS commands with the privileges of the root user on the web server.
Successful exploitation of this vulnerability requires &amp;ldquo;Softaculous&amp;rdquo; and/or &amp;ldquo;SitePad&amp;rdquo; to be installed through the Scripts Manager.</description>
    </item>
    
    <item>
      <title>Coppermine Photo Gallery &lt;= 1.4.18 Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-26/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-26/</guid>
      <description>Description: Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
References:  CVE-2008-3486 BID-30480 EDB-6178  Disclosure Date: July 31, 2008</description>
    </item>
    
    <item>
      <title>Coppermine Photo Gallery &lt;= 1.4.18 Path Disclosure Weakness</title>
      <link>https://karmainsecurity.com/vuln-25/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-25/</guid>
      <description>Description: themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
References:  CVE-2008-3481 EDB-6178  Disclosure Date: July 31, 2008</description>
    </item>
    
    <item>
      <title>CrafterCMS &lt;= 4.0.2 Multiple Reflected Cross-Site Scripting Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2023-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-09/</guid>
      <description>• Software Link: https://craftercms.org
• Affected Versions: Version 4.0.2 and prior versions. Version 3.1.27 and prior versions.
• Vulnerabilities Description: There are multiple Reflected Cross-Site Scripting vulnerabilities affecting CrafterCMS. The vulnerabilities exist in every API endpoint that reflect some input parameter and do produce XML responses. Following are some examples:
 /api/1/site/url/transform – url and transformerName parameters are affected /api/1/site/content_store/children – url parameter is affected /api/1/site/content_store/item – url parameter is affected  • Solution: Upgrade to version 4.</description>
    </item>
    
    <item>
      <title>CubeCart &lt;= 5.2.0 (cubecart.class.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-02/</guid>
      <description>• Software Link: http://www.cubecart.com
• Affected Versions: All versions from 5.0.0 to 5.2.0.
• Vulnerability Description: The vulnerable code is located in the Cubecart::_basket() method defined in the /classes/cubecart.class.php script:
519// Update shipping values 520if (isset($_POST[&amp;#39;shipping&amp;#39;]) &amp;amp;&amp;amp; !empty($_POST[&amp;#39;shipping&amp;#39;])) { 521 $GLOBALS[&amp;#39;cart&amp;#39;]-&amp;gt;set(&amp;#39;shipping&amp;#39;, unserialize(base64url_decode($_POST[&amp;#39;shipping&amp;#39;]))); 522 if (!isset($_POST[&amp;#39;proceed&amp;#39;])) { 523 httpredir(currentPage()); 524 } 525} User input passed through the $_POST[&amp;lsquo;shipping&amp;rsquo;] parameter is not properly sanitized before being used in an unserialize() call at line 521.</description>
    </item>
    
    <item>
      <title>DataLife Engine 9.7 (preview.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-01/</guid>
      <description>• Software Link: http://dleviet.com
• Affected Version: 9.7 only.
• Vulnerability Description: The vulnerable code is located in the /engine/preview.php script:
246$c_list = implode (&amp;#39;,&amp;#39;, $_REQUEST[&amp;#39;catlist&amp;#39;]); 247 248if( strpos( $tpl-&amp;gt;copy_template, &amp;#34;[catlist=&amp;#34; ) !== false ) { 249 $tpl-&amp;gt;copy_template = preg_replace( &amp;#34;#\\[catlist=(.+?)\\](.*?)\\[/catlist\\]#ies&amp;#34;, &amp;#34;check_category(&amp;#39;\\1&amp;#39;, &amp;#39;\\2&amp;#39;, &amp;#39;{$c_list}&amp;#39;)&amp;#34;, $tpl-&amp;gt;copy_template ); 250} 251 252if( strpos( $tpl-&amp;gt;copy_template, &amp;#34;[not-catlist=&amp;#34; ) !== false ) { 253 $tpl-&amp;gt;copy_template = preg_replace( &amp;#34;#\\[not-catlist=(.+?)\\](.*?)\\[/not-catlist\\]#ies&amp;#34;, &amp;#34;check_category(&amp;#39;\\1&amp;#39;, &amp;#39;\\2&amp;#39;, &amp;#39;{$c_list}&amp;#39;, false)&amp;#34;, $tpl-&amp;gt;copy_template ); 254} User supplied input passed through the $_REQUEST[&amp;lsquo;catlist&amp;rsquo;] parameter is not properly sanitized before being used in a preg_replace() call with the e modifier at lines 249 and 253.</description>
    </item>
    
    <item>
      <title>DeluxeBB &lt;= 1.2 (admincp.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-14/</guid>
      <description>Description: Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.
References:  CVE-2008-2195 BID-29062 EDB-5550  Disclosure Date: May 5, 2008</description>
    </item>
    
    <item>
      <title>DeluxeBB &lt;= 1.2 (forums.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-15/</guid>
      <description>Description: DeluxeBB contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the &amp;lsquo;forums.php&amp;rsquo; script not properly sanitizing user-supplied input to the &amp;lsquo;sort&amp;rsquo; variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
References:  CVE-2008-2194 BID-29062 EDB-5550  Disclosure Date: May 5, 2008</description>
    </item>
    
    <item>
      <title>Docebo &lt;= 3.5.0.3 (doceboCore/lib/lib.regset.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-11/</guid>
      <description>Description: SQL injection vulnerability in the autoDetectRegion() function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.
References:  CVE-2008-7153 BID-27211 EDB-4879  Disclosure Date: January 9, 2008</description>
    </item>
    
    <item>
      <title>Docebo &lt;= 3.5.0.3 Multiple Path Disclosure Weaknesses</title>
      <link>https://karmainsecurity.com/vuln-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-10/</guid>
      <description>Description: Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3) lib/lib.domxml5.php, or (4) menu/menu_over.php in doceboCore/; or (5) class/class.conf_cms.php, (6) lib/lib.compose.php, (7) modules/chat/teleskill.php, or (8) class/class.admin_menu_cms.php in doceboCms/; which reveals the installation path in an error message.
References:  CVE-2008-7154 BID-27211 EDB-4879  Disclosure Date: January 9, 2008</description>
    </item>
    
    <item>
      <title>docsify &lt;= 4.12.0 DOM-based Cross-Site Scripting Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2021-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2021-02/</guid>
      <description>• Software Link: https://docsify.js.org
• Affected Versions: Version 4.12.0 and prior versions.
• Vulnerability Description: The vulnerability exists due to an incomplete fix for CVE-2020-7680. When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. This can be exploited to inject arbitrary HTML code and carry out DOM-based Cross-Site Scripting (XSS) attacks.
• Solution: Upgrade to version 4.</description>
    </item>
    
    <item>
      <title>Dokeos LMS &lt;= 1.8.5 (tablesort.lib.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-38/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-38/</guid>
      <description>Description: Dokeos contains a flaw that may allow a malicious user to execute arbitrary PHP code. The issue is due to user-supplied input passed via the &amp;lsquo;tablename_column&amp;rsquo; parameter to the whoisonline.php script is not properly sanitized before being used in a call to the create_function() PHP function in the main/inc/lib/tablesort.lib.php script.
References:  BID-34633 EDB-8499  Disclosure Date: April 21, 2009</description>
    </item>
    
    <item>
      <title>Dolphin &lt;= 7.0.7 PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-52/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-52/</guid>
      <description>Description: Dolphin contains a flaw which allows a remote attacker to inject and execute arbitrary PHP code. The issue is due to user-supplied input passed through the &amp;lsquo;bubbles&amp;rsquo; parameter to the member_menu_queries.php script isn&amp;rsquo;t properly sanitized before being used in a call to the eval() PHP function.
References:  BID-50185 EDB-17994  Disclosure Date: October 18, 2011</description>
    </item>
    
    <item>
      <title>Dotclear &lt;= 2.6.2 (categories.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-07/</guid>
      <description>• Software Link: http://dotclear.org
• Affected Versions: Version 2.6.2 and probably prior versions.
• Vulnerability Description: The vulnerable code is located in /admin/categories.php:
70# Update order 71if (!empty($_POST[&amp;#39;save_order&amp;#39;]) &amp;amp;&amp;amp; !empty($_POST[&amp;#39;categories_order&amp;#39;])) { 72 $categories = json_decode($_POST[&amp;#39;categories_order&amp;#39;]); 73 74 foreach ($categories as $category) { 75 if (!empty($category-&amp;gt;item_id)) { 76 $core-&amp;gt;blog-&amp;gt;updCategoryPosition($category-&amp;gt;item_id, $category-&amp;gt;left, $category-&amp;gt;right); 77 } 78 } 79 80 dcPage::addSuccessNotice(__(&amp;#39;Categories have been successfully reordered.&amp;#39;)); 81 http::redirect(&amp;#39;categories.php&amp;#39;); 82} User input passed through the $_POST[&amp;lsquo;categories_order&amp;rsquo;] parameter is not properly sanitized before being used in a call to the dcBlog::updCategoryPosition() method at line 76.</description>
    </item>
    
    <item>
      <title>Dotclear &lt;= 2.6.2 (Media Manager) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-06/</guid>
      <description>• Software Link: http://dotclear.org
• Affected Versions: Version 2.6.2 and probably prior versions.
• Vulnerability Description: The vulnerability exists because of the filemanager::isFileExclude() method not properly verifying the extension of uploaded files. This method just checks whether the uploaded file name matches the &amp;ldquo;exclude_pattern&amp;rdquo; regular expression, which by default is set to /\.php$/i. This could be exploited to execute arbitrary PHP code by uploading a file with multiple extensions or other extensions (like .</description>
    </item>
    
    <item>
      <title>Dotclear &lt;= 2.6.2 (XML-RPC Interface) Authentication Bypass Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-05/</guid>
      <description>• Software Link: http://dotclear.org
• Affected Versions: Version 2.6.2 and probably prior versions.
• Vulnerability Description: The vulnerable code is located in the dcXmlRpc::setUser() method (inc/core/class.dc.xmlrpc.php):
264private function setUser($user_id,$pwd) 265{ 266 if ($this-&amp;gt;core-&amp;gt;auth-&amp;gt;userID() == $user_id) { 267 return true; 268 } 269 270 if ($this-&amp;gt;core-&amp;gt;auth-&amp;gt;checkUser($user_id,$pwd) !== true) { 271 throw new Exception(&amp;#39;Login error&amp;#39;); 272 } 273 274 return true; 275} The vulnerability exists because of the method not properly verifying the provided password before being used in a call to the dcAuth::checkUser() method at line 270.</description>
    </item>
    
    <item>
      <title>Drake CMS &lt;= 0.4.11 (guestbook.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-12/</guid>
      <description>Description: SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.
References:  CVE-2008-6475 BID-28656 EDB-5391  Disclosure Date: April 7, 2008</description>
    </item>
    
    <item>
      <title>Drupal H5P Module &lt;= 2.0.0 (isValidPackage) Zip Slip Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2022-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2022-06/</guid>
      <description>• Software Link: https://www.drupal.org/project/h5p
• Affected Versions: Version 2.0.0-alpha2 and prior versions.
Version 7.x-1.50 and prior versions.
• Vulnerability Description: The vulnerability is located within the H5PValidator::isValidPackage() method. This implements the following check in order to skip any file or folder starting with a dot or underscore within the uploaded h5p archive:
891$fileName = $zip-&amp;gt;statIndex($i)[&amp;#39;name&amp;#39;]; 892 893if (preg_match(&amp;#39;/(^[\._]|\/[\._])/&amp;#39;, $fileName) !== 0) { 894 continue; // Skip any file or folder starting with a .</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 (filesystem.class.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-59/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-59/</guid>
      <description>Description: eFront contains a flaw related to the libraries/filesystem.class.php script which does not properly verify or sanitize user-uploaded files. This allows a remote attacker to upload and execute arbitrary PHP code.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 (LMSFunctions.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-57/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-57/</guid>
      <description>Description: eFront contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the www/js/LMSFunctions.php script not properly sanitizing user-supplied input passed via the &amp;lsquo;view_unit&amp;rsquo; parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 (periodic_updater.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-58/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-58/</guid>
      <description>Description: eFront contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the www/periodic_updater.php script not properly sanitizing user-supplied input passed via the &amp;lsquo;HTTP_REFERER&amp;rsquo; parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 (save_template.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-60/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-60/</guid>
      <description>Description: eFront contains a flaw which allows a remote attacker to inject and execute arbitrary PHP code. The issue is due to the www/editor/tiny_mce/plugins/save_template/save_template.php script which fails to properly sanitize user-supplied input passed via the &amp;lsquo;templateName&amp;rsquo; and &amp;lsquo;templateContent&amp;rsquo; parameters before use it in a call to the file_put_contents() PHP function.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 (send_notifications.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-56/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-56/</guid>
      <description>Description: eFront contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the www/send_notifications.php script not properly sanitizing user-supplied input passed via the &amp;lsquo;sent_notification_id&amp;rsquo; parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 (student.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-54/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-54/</guid>
      <description>Description: eFront contains a flaw related to the student.php script which fails to properly sanitize user-supplied input passed via the &amp;lsquo;course&amp;rsquo; and &amp;lsquo;from_course&amp;rsquo; parameters before use it to instanciate a new EfrontCourse object. This can be exploited to inject and execute arbitrary PHP code.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eFront &lt;= 3.6.10 Authentication Bypass / Privilege Escalation Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-55/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-55/</guid>
      <description>Description: eFront contains a flaw related to the index.php script which fails to properly sanitize user-supplied input passed via the &amp;lsquo;cookie_login&amp;rsquo; cookie parameter before use it to instanciate a new user object. This can be exploited to bypass the authentication mechanism and to escalate privilege.
References:  BID-50391 EDB-18036 http://forum.efrontlearning.net/viewtopic.php?t=3501  Disclosure Date: October 27, 2011</description>
    </item>
    
    <item>
      <title>eSyndiCat Link Exchange Script (suggest-link.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-4/</guid>
      <description>Description: SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
References:  CVE-2007-6543 BID-27029 EDB-4791  Disclosure Date: December 25, 2007</description>
    </item>
    
    <item>
      <title>ExpressionEngine &lt;= 6.0.2 (Translate::save) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2021-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2021-03/</guid>
      <description>• Software Link: https://expressionengine.com
• Affected Versions: Version 6.0.2 and prior versions.
Version 5.4.1 and prior versions.
• Vulnerability Description: The vulnerable code is located in the ExpressionEngine\Controller\Utilities\Translate::save() method:
362private function save($language, $file) 363{ 364 365 $file = ee()-&amp;gt;security-&amp;gt;sanitize_filename($file); 366 367 $dest_dir = $this-&amp;gt;languages_dir . $language . &amp;#39;/&amp;#39;; 368 $filename = $file . &amp;#39;_lang.php&amp;#39;; 369 $dest_loc = $dest_dir . $filename; 370 371 $str = &amp;#39;&amp;lt;?php&amp;#39; . &amp;#34;\n&amp;#34; . &amp;#39;$lang = array(&amp;#39; .</description>
    </item>
    
    <item>
      <title>Feed on Feeds &lt;= 0.5 (fof-main.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-51/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-51/</guid>
      <description>Description: Feed on Feeds contains a flaw which allows a remote attacker to inject and execute arbitrary PHP code. The issue is due to user-supplied input passed through the $_POST[&amp;lsquo;feed_order&amp;rsquo;] parameter to set-prefs.php isn&amp;rsquo;t properly sanitized before being used in a call to the create_function() PHP function.
References:  BID-49901 EDB-17911  Disclosure Date: September 30, 2011</description>
    </item>
    
    <item>
      <title>FLABER &lt;= 1.1 (update_xml.php) Arbitrary File Overwrite Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-13/</guid>
      <description>Description: function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.
References:  CVE-2008-6490 EDB-5407  Disclosure Date: April 8, 2008</description>
    </item>
    
    <item>
      <title>Flux CMS &lt;= 1.5.0 (loadsave.php) Arbitrary File Overwrite Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-21/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-21/</guid>
      <description>Description: webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.
References:  CVE-2008-2686 BID-29618 EDB-5767  Disclosure Date: June 9, 2008</description>
    </item>
    
    <item>
      <title>FreeWebshop &lt;= 2.2.9 R2  PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-66/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-66/</guid>
      <description>Description: Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier allows remote attackers to inject arbitrary PHP code into data.php via the selected document, as demonstrated by a call to ajax_file_cut.php and then to ajax_save_name.php.
References:  CVE-2011-5147 BID-50694 EDB-18121 http://www.freewebshop.org/forum/index.php?topic=5235  Disclosure Date: November 16, 2011</description>
    </item>
    
    <item>
      <title>GdPicture Light Imaging Toolkit &lt;= 4.7.1 Arbitrary File Overwrite Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-28/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-28/</guid>
      <description>Description: The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF() method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.</description>
    </item>
    
    <item>
      <title>GdPicture Pro Imaging SDK &lt;= 5.7.1 Arbitrary File Overwrite Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-29/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-29/</guid>
      <description>Description: The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF() method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.</description>
    </item>
    
    <item>
      <title>GetSimple CMS &lt;= 3.3.4 (api.php) XML External Entity Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-17/</guid>
      <description>• Software Link: http://get-simple.info
• Affected Versions: All versions from 3.1.1 to 3.3.4.
• Vulnerability Description: The vulnerable code is located in the /admin/api.php script:
22#step 2 - setup request 23$in = simplexml_load_string($_POST[&amp;#39;data&amp;#39;], &amp;#39;SimpleXMLExtended&amp;#39;, LIBXML_NOCDATA); 24$request = new API_Request(); 25$request-&amp;gt;add_data($in); User input passed via the &amp;ldquo;data&amp;rdquo; POST parameter is not properly sanitized before being used in a call to the simplexml_load_string() PHP function at line 23. This can be exploited to carry out XML External Entity (XXE) attacks, resulting in arbitrary file disclosures.</description>
    </item>
    
    <item>
      <title>GFI Kerio Control &lt;= 9.4.5 Multiple HTTP Response Splitting Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2024-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-07/</guid>
      <description>• Software Links: https://gfi.ai/products-and-solutions/network-security-solutions/keriocontrol
http://download.kerio.com
• Affected Versions: All versions from 9.2.5 to 9.4.5.
• Vulnerabilities Description: There are multiple HTTP Response Splitting vulnerabilities in GFI Kerio Control. Following are some of the affected pages:
 /nonauth/addCertException.cs /nonauth/guestConfirm.cs /nonauth/expiration.cs  User input passed to these pages via the &amp;ldquo;dest&amp;rdquo; GET parameter is not properly sanitized before being used to generate a &amp;ldquo;Location&amp;rdquo; HTTP header in a 302 HTTP response. Specifically, the application does not correctly filter/remove linefeed (LF) characters.</description>
    </item>
    
    <item>
      <title>ImpressCMS &lt;= 1.4.2 (autologin.php) Authentication Bypass Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2022-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2022-01/</guid>
      <description>• Software Link: https://www.impresscms.org
• Affected Versions: Version 1.4.2 and prior versions.
• Vulnerability Description: The vulnerability is located in the /plugins/preloads/autologin.php script:
45$uname = $myts-&amp;gt;stripSlashesGPC($autologinName); 46$pass = $myts-&amp;gt;stripSlashesGPC($autologinPass); 47if (empty($uname) || is_numeric($pass)) { 48 $user = false ; 49} else { 50 // V3 51 $uname4sql = addslashes($uname); 52 $criteria = new icms_db_criteria_Compo(new icms_db_criteria_Item(&amp;#39;login_name&amp;#39;, $uname4sql)); 53 $user_handler = icms::handler(&amp;#39;icms_member_user&amp;#39;); 54 $users = $user_handler-&amp;gt;getObjects($criteria, false); 55 if (empty($users) || count($users) !</description>
    </item>
    
    <item>
      <title>ImpressCMS &lt;= 1.4.2 (findusers.php) Incorrect Access Control Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2022-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2022-03/</guid>
      <description>• Software Link: https://www.impresscms.org
• Affected Versions: Version 1.4.2 and prior versions.
• Vulnerability Description: The vulnerability is located in the /include/findusers.php script:
16include &amp;#34;../mainfile.php&amp;#34;; 17xoops_header(false); 18 19$denied = true; 20if (!empty($_REQUEST[&amp;#39;token&amp;#39;])) { 21 if (icms::$security-&amp;gt;validateToken($_REQUEST[&amp;#39;token&amp;#39;], false)) { 22 $denied = false; 23 } 24} elseif (is_object(icms::$user) &amp;amp;&amp;amp; icms::$user-&amp;gt;isAdmin()) { 25 $denied = false; 26} 27if ($denied) { 28 icms_core_Message::error(_NOPERM); 29 exit(); 30} This script should be accessible to authenticated users only.</description>
    </item>
    
    <item>
      <title>ImpressCMS &lt;= 1.4.2 (image-edit.php) Path Traversal Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2022-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2022-02/</guid>
      <description>• Software Link: https://www.impresscms.org
• Affected Versions: Version 1.4.2 and prior versions.
• Vulnerability Description: The vulnerability is located in the /libraries/image-editor/image-edit.php script:
161if (@copy ( ICMS_IMANAGER_FOLDER_PATH . &amp;#39;/temp/&amp;#39; . $simage_temp, $categ_path . $simage-&amp;gt;getVar ( &amp;#39;image_name&amp;#39; ) )) { 162 if (@unlink ( ICMS_IMANAGER_FOLDER_PATH . &amp;#39;/temp/&amp;#39; . $simage_temp )) { 163 $msg = _MD_AM_DBUPDATED; 190} else { 191 if (copy ( ICMS_IMANAGER_FOLDER_PATH . &amp;#39;/temp/&amp;#39; . $simage_temp, $categ_path . $imgname )) { 192 @unlink ( ICMS_IMANAGER_FOLDER_PATH .</description>
    </item>
    
    <item>
      <title>ImpressCMS &lt;= 1.4.3 (findusers.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2022-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2022-04/</guid>
      <description>• Software Link: https://www.impresscms.org
• Affected Versions: Version 1.4.3 and prior versions.
• Vulnerability Description: The vulnerability is located in the /include/findusers.php script:
281$total = $user_handler-&amp;gt;getUserCountByGroupLink(@$_POST[&amp;#34;groups&amp;#34;], $criteria); 282 283$validsort = array(&amp;#34;uname&amp;#34;, &amp;#34;email&amp;#34;, &amp;#34;last_login&amp;#34;, &amp;#34;user_regdate&amp;#34;, &amp;#34;posts&amp;#34;); 284$sort = (!in_array($_POST[&amp;#39;user_sort&amp;#39;], $validsort)) ? &amp;#34;uname&amp;#34; : $_POST[&amp;#39;user_sort&amp;#39;]; 285$order = &amp;#34;ASC&amp;#34;; 286if (isset($_POST[&amp;#39;user_order&amp;#39;]) &amp;amp;&amp;amp; $_POST[&amp;#39;user_order&amp;#39;] == &amp;#34;DESC&amp;#34;) { 287 $order = &amp;#34;DESC&amp;#34;; 288} 289 290$criteria-&amp;gt;setSort($sort); 291$criteria-&amp;gt;setOrder($order); 292$criteria-&amp;gt;setLimit($limit); 293$criteria-&amp;gt;setStart($start); 294$foundusers = $user_handler-&amp;gt;getUsersByGroupLink(@$_POST[&amp;#34;groups&amp;#34;], $criteria, TRUE); User input passed through the &amp;ldquo;groups&amp;rdquo; POST parameter is not properly sanitized before being used in a call to the icms_member_Handler::getUserCountByGroupLink() and icms_member_Handler::getUsersByGroupLink() methods at lines 281 and 294.</description>
    </item>
    
    <item>
      <title>Invision Community &lt;= 4.7.15 (store.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2024-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-02/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: All versions from 4.4.0 to 4.7.15.
• Vulnerability Description: The vulnerability is located in the /applications/nexus/modules/front/store/store.php script.
Specifically, into the IPS\nexus\modules\front\store\_store::_categoryView() method:
126	/* Apply Filters */ 127	if ( isset( \IPS\Request::i()-&amp;gt;filter ) and \is_array( \IPS\Request::i()-&amp;gt;filter ) ) 128	{ 129	$url = $url-&amp;gt;setQueryString( &amp;#39;filter&amp;#39;, \IPS\Request::i()-&amp;gt;filter ); 130	foreach ( \IPS\Request::i()-&amp;gt;filter as $filterId =&amp;gt; $allowedValues ) 131	{ 132	$where[] = array( \IPS\Db::i()-&amp;gt;findInSet( &amp;#34;filter{$filterId}.</description>
    </item>
    
    <item>
      <title>Invision Community &lt;= 4.7.20 (calendar/view.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-06/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: Certain 4.x versions before 4.7.21.
• Vulnerability Description: The vulnerability is located within the /applications/calendar/modules/front/calendar/view.php script.
Specifically, in the IPS\calendar\modules\front\calendar\view::search() method:
725	if( \IPS\GeoLocation::enabled() ) 726	{ 727	if( \IPS\Request::i()-&amp;gt;location ) 728	{ 729	/* Is it a location? */ 730	$locations = static::geocodeLocation( \IPS\Request::i()-&amp;gt;location, FALSE ); 731	if( \is_array( $locations ) and \count( $locations ) ) 732	{ 733	if( $locations[0][&amp;#39;value&amp;#39;] ) 734	{ 735	$having[] = &amp;#34;( event_title LIKE CONCAT( &amp;#39;%&amp;#39;, &amp;#39;&amp;#34; .</description>
    </item>
    
    <item>
      <title>Invision Community &lt;= 4.7.20 (toolbar.php) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2024-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-03/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: Version 4.7.20 and prior versions.
• Vulnerability Description: The vulnerability is located in the /applications/core/modules/admin/editor/toolbar.php script.
Specifically, into the IPS\core\modules\admin\editor\_toolbar::addPlugin() method, which will handle the upload of a ZIP file, trying to extract its content into the /applications/core/interface/ckeditor/ckeditor/plugins/ directory; if the ZIP archive does not include a plugin.js file, then the extracted ZIP content will be recursively deleted from the file system, otherwise it will stay there.</description>
    </item>
    
    <item>
      <title>Invision Community &lt;= 5.0.6 (customCss) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-02/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: All versions from 5.0.0 to 5.0.6.
• Vulnerability Description: The vulnerability is located in the /applications/core/modules/front/system/themeeditor.php script.
Specifically, into the IPS\core\modules\front\system\themeeditor::customCss() method:
359	/** 360* Parse Custom CSS so that we can properly handle any 361* resource tags, etc 362* 363* @return void 364*/ 365	protected function customCss() : void 366	{ 367	$functionName = &amp;#34;css_&amp;#34; . uniqid(); 368	Theme::makeProcessFunction( Theme::fixResourceTags( (string) Request::i()-&amp;gt;content, &amp;#39;front&amp;#39; ), $functionName, &amp;#39;&amp;#39;, FALSE, TRUE ); 369 370	$fqFunc	= &amp;#39;IPS\\Theme\\&amp;#39;.</description>
    </item>
    
    <item>
      <title>Invision Community &lt;= 5.0.7 (oauth/callback) Reflected Cross-Site Scripting Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-05/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: Certain 4.x versions before 4.7.21.
All 5.x versions before 5.0.8.
• Vulnerability Description: User input passed through the &amp;ldquo;state&amp;rdquo; POST parameter to the /oauth/callback/index.php script is not properly sanitized before being used to generate HTML output. This can be exploited by attackers to perform Reflected Cross-Site Scripting (XSS) attacks.
• Proof of Concept: The vulnerability can be exploited by tricking a victim user into opening an HTML page like the following:</description>
    </item>
    
    <item>
      <title>Invision Power Board &lt;= 3.3.4 (core.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-86/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-86/</guid>
      <description>Description: Invision Power Board contains a flaw related to the IPSCookie::get() method defined in the admin/sources/base/core.php script. User input passed through cookies is not properly sanitized before being used in a call to the unserialize() function. With a specially crafted serialized object a remote attacker might be able to create a file containing arbitrary PHP code abusing the __destruct() method of the dbMain class.
References:  CVE-2012-5692 BID-56288 EDB-22398  Disclosure Date: November 1, 2012</description>
    </item>
    
    <item>
      <title>IPS Community Suite &lt;= 4.1.12.3 Autoloaded PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-11/</guid>
      <description>• Software Link: https://invisionpower.com
• Affected Versions: Version 4.1.12.3 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /applications/core/modules/front/system/content.php script:
38$class = &amp;#39;IPS\\&amp;#39; . implode( &amp;#39;\\&amp;#39;, explode( &amp;#39;_&amp;#39;, \IPS\Request::i()-&amp;gt;content_class ) ); 39 40if ( ! class_exists( $class ) or ! in_array( &amp;#39;IPS\Content&amp;#39;, class_parents( $class ) ) ) 41{ 42 \IPS\Output::i()-&amp;gt;error( &amp;#39;node_error&amp;#39;, &amp;#39;2S226/2&amp;#39;, 404, &amp;#39;&amp;#39; ); 43} User input passed through the &amp;ldquo;content_class&amp;rdquo; request parameter is not properly sanitized before being used in a call to the class_exists() PHP function at line 40.</description>
    </item>
    
    <item>
      <title>IPS Community Suite &lt;= 4.5.4 (Downloads REST API) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2021-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2021-01/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: Version 4.5.4 and prior versions.
• Vulnerability Description: The vulnerability is located within the /applications/downloads/api/files.php script, specifically into the GETindex() method:
48public function GETindex() 49{ 50 /* Where clause */ 51 $where = array(); 52 $sortBy = NULL; 53 54 /* Sort by popular files */ 55 if( \IPS\Request::i()-&amp;gt;sortBy == &amp;#39;popular&amp;#39; ) 56 { 57 \IPS\Request::i()-&amp;gt;sortDir = \IPS\Request::i()-&amp;gt;sortDir ?: &amp;#39;ASC&amp;#39;; 58 $sortBy = &amp;#39;file_rating &amp;#39; .</description>
    </item>
    
    <item>
      <title>IPS Community Suite &lt;= 4.5.4.2 (previewBlock) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2021-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2021-04/</guid>
      <description>• Software Link: https://invisioncommunity.com
• Affected Versions: Version 4.5.4.2 and prior versions.
• Vulnerability Description: The vulnerability exists because the IPS\cms\modules\front\pages\_builder::previewBlock() method allows to pass arbitrary content to the IPS\_Theme::runProcessFunction() method, which will be used in a call to the eval() PHP function. This can be exploited to inject and execute arbitrary PHP code.
Successful exploitation of this vulnerability requires an account with permission to manage the sidebar (such as a Moderator or Administrator) and the “cms” application to be enabled.</description>
    </item>
    
    <item>
      <title>ISPConfig &lt;= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-13/</guid>
      <description>• Software Link: https://www.ispconfig.org
• Affected Versions: Version 3.2.11 and prior versions.
• Vulnerability Description: User input passed through the &amp;ldquo;records&amp;rdquo; POST parameter to /admin/language_edit.php is not properly sanitized before being used to dynamically generate PHP code that will be executed by the application. This can be exploited by malicious administrator users to inject and execute arbitrary PHP code on the web server.
• Proof of Concept: https://karmainsecurity.com/pocs/CVE-2023-46818.php
• Solution: Upgrade to version 3.</description>
    </item>
    
    <item>
      <title>JAKCMS PRO &lt;= 2.2.5 Session Variable Overloading Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-50/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-50/</guid>
      <description>Description: JAKCMS has a flaw related to the js/editor/plugins/jakadminexplorer/php/session.php script which does not properly verify a session variable. This can be exploited to bypass the authentication mechanism and gain access to certain administrative functions.
References:  BID-49737 EDB-17882  Disclosure Date: September 22, 2011</description>
    </item>
    
    <item>
      <title>JAKCMS PRO &lt;= 2.2.5 Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-49/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-49/</guid>
      <description>Description: JAKCMS contains a flaw related to the js/editor/plugins/jakadminexplorer/php/action.php script which does not properly verify or sanitize user-uploaded files. This allows a remote attacker to upload and execute arbitrary PHP code.
References:  BID-49737 EDB-17882  Disclosure Date: September 22, 2011</description>
    </item>
    
    <item>
      <title>Joomla! &lt;= 3.0.2 (highlight.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-03/</guid>
      <description>• Software Link: http://www.joomla.org
• Affected Versions: Version 3.0.2 and earlier 3.0.x versions.
Version 2.5.8 and earlier 2.5.x versions.
• Vulnerability Description: The vulnerable code is located in /plugins/system/highlight/highlight.php:
56// Get the terms to highlight from the request. 57$terms = $input-&amp;gt;request-&amp;gt;get(&amp;#39;highlight&amp;#39;, null, &amp;#39;base64&amp;#39;); 58$terms = $terms ? unserialize(base64_decode($terms)) : null; User input passed through the &amp;ldquo;highlight&amp;rdquo; parameter is not properly sanitized before being used in an unserialize() call at line 58.</description>
    </item>
    
    <item>
      <title>Joomla! &lt;= 3.0.3 (remember.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-04/</guid>
      <description>• Software Link: http://www.joomla.org
• Affected Versions: Version 3.0.3 and earlier 3.0.x versions.
Version 2.5.9 and earlier 2.5.x versions.
• Vulnerability Description: The vulnerable code is located in /plugins/system/remember/remember.php:
34$hash = JApplication::getHash(&amp;#39;JLOGIN_REMEMBER&amp;#39;); 35 36if ($str = JRequest::getString($hash, &amp;#39;&amp;#39;, &amp;#39;cookie&amp;#39;, JREQUEST_ALLOWRAW | JREQUEST_NOTRIM)) 37{ 38 // Create the encryption key, apply extra hardening using the user agent string. 39 // Since we&amp;#39;re decoding, no UA validity check is required. 40 $privateKey = JApplication::getHash(@$_SERVER[&amp;#39;HTTP_USER_AGENT&amp;#39;]); 41 42 $key = new JCryptKey(&amp;#39;simple&amp;#39;, $privateKey, $privateKey); 43 $crypt = new JCrypt(new JCryptCipherSimple, $key); 44 $str = $crypt-&amp;gt;decrypt($str); 45 $cookieData = @unserialize($str); User input passed through cookies is not properly sanitized before being used in an unserialize() call at line 45.</description>
    </item>
    
    <item>
      <title>Joomla! &lt;= 4.1.0 (Tar.php) Zip Slip Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2022-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2022-05/</guid>
      <description>• Software Link: https://www.joomla.org
• Affected Versions: Version 4.1.0 and prior versions.
Version 3.10.6 and prior versions.
• Vulnerability Description: The vulnerability is located in the /libraries/vendor/joomla/archive/src/Tar.php script.
Specifically, into the Joomla\Archive\Tar::extract() method:
113$this-&amp;gt;getTarInfo($this-&amp;gt;data); 114 115for ($i = 0, $n = \count($this-&amp;gt;metadata); $i &amp;lt; $n; $i++) 116{ 117 $type = strtolower($this-&amp;gt;metadata[$i][&amp;#39;type&amp;#39;]); 118 119 if ($type == &amp;#39;file&amp;#39; || $type == &amp;#39;unix file&amp;#39;) 120 { 121 $buffer = $this-&amp;gt;metadata[$i][&amp;#39;data&amp;#39;]; 122 $path = Path::clean($destination .</description>
    </item>
    
    <item>
      <title>La-Nai CMS &lt;= 1.2.16 (FCKEditor) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-17/</guid>
      <description>Description: La-Nai CMS contains a flaw that allows a remote user to execute arbitrary PHP code. The vulnerability is caused due to an error in the handling of file uploads in the include/fckeditor/editor/filemanager/upload/php/upload.php script, when a file name has multiple file extensions. This can be exploited to upload malicious PHP scripts.
References:  CVE-2007-5156 EDB-5618  Disclosure Date: May 14, 2008</description>
    </item>
    
    <item>
      <title>Lanius CMS &lt;= 0.5.2 (upload.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-37/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-37/</guid>
      <description>Description: Lanius CMS contains a flaw that allows a remote user to upload and execute arbitrary PHP code. The vulnerability is caused due to an error in the handling of file uploads in the includes/upload.php script.
References:  BID-34415 EDB-8362  Disclosure Date: April 7, 2009</description>
    </item>
    
    <item>
      <title>LightBlog &lt;= 9.9.2 (register.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-40/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-40/</guid>
      <description>Description: LightBlog contains a flaw that allows malicious users to execute arbitrary PHP code. The issue is due to user-supplied input passed via multiple parameters to register.php is not properly sanitized before being stored within a php file.
References:  EDB-8543  Disclosure Date: April 27, 2009</description>
    </item>
    
    <item>
      <title>LightBlog &lt;= 9.9.2 Authentication Bypass / Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-39/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-39/</guid>
      <description>Description: The issue is due to user-suplpied input passed via the &amp;lsquo;Lightblog_username&amp;rsquo; cookie to the check_user.php script is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal attacks, or to bypass the authentication mechanism.
References:  EDB-8543  Disclosure Date: April 27, 2009</description>
    </item>
    
    <item>
      <title>LinPHA &lt;= 1.3.1 (new_images.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-1/</guid>
      <description>Description: LinPHA contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /include/img_view.class.php script not properly sanitizing user-supplied input passed via the &amp;lsquo;order&amp;rsquo; parameter to the include/img_view.class.php script. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  CVE-2007-4053 BID-25119 EDB-4242  Disclosure Date: July 29, 2007</description>
    </item>
    
    <item>
      <title>Magento &lt;= 1.9.2 (catalogProductCreate) Autoloaded File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-04/</guid>
      <description>• Software Link: http://magento.com
• Affected Versions: Version 1.9.2 and prior versions.
• Vulnerability Description: The vulnerability is caused by the &amp;ldquo;catalogProductCreate&amp;rdquo; SOAP API implementation, which is defined into the /app/code/core/Mage/Catalog/Model/Product/Api/V2.php script:
109public function create($type, $set, $sku, $productData, $store = null) 110{ 111 if (!$type || !$set || !$sku) { 112 $this-&amp;gt;_fault(&amp;#39;data_invalid&amp;#39;); 113 } 114 115 $this-&amp;gt;_checkProductTypeExists($type); 116 $this-&amp;gt;_checkProductAttributeSet($set); 117 118 /** @var $product Mage_Catalog_Model_Product */ 119 $product = Mage::getModel(&amp;#39;catalog/product&amp;#39;); 120 $product-&amp;gt;setStoreId($this-&amp;gt;_getStoreId($store)) 121 -&amp;gt;setAttributeSetId($set) 122 -&amp;gt;setTypeId($type) 123 -&amp;gt;setSku($sku); 124 125 if (!</description>
    </item>
    
    <item>
      <title>Magento &lt;= 1.9.2.2 (RSS Feed) Information Disclosure Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-02/</guid>
      <description>• Software Link: https://magento.com
• Affected Versions: Version 1.9.2.2 and prior versions.
• Vulnerability Description: The vulnerability is located in the /app/code/core/Mage/Rss/Helper/Order.php script, specifically into the getOrderByStatusUrlKey() method of the Mage_Rss_Helper_Order class, which is the method being called when dispatching RSS orders&#39; feed requests:
83public function getOrderByStatusUrlKey($key) 84{ 85 $data = json_decode(base64_decode($key), true); 86 if (!is_array($data) || !isset($data[&amp;#39;order_id&amp;#39;]) || !isset($data[&amp;#39;increment_id&amp;#39;]) 87 || !isset($data[&amp;#39;customer_id&amp;#39;]) 88 ) { 89 return null; 90 } 91 92 /** @var $order Mage_Sales_Model_Order */ 93 $order = Mage::getModel(&amp;#39;sales/order&amp;#39;)-&amp;gt;load($data[&amp;#39;order_id&amp;#39;]); 94 if ($order-&amp;gt;getId() 95 &amp;amp;&amp;amp; $order-&amp;gt;getIncrementId() == $data[&amp;#39;increment_id&amp;#39;] 96 &amp;amp;&amp;amp; $order-&amp;gt;getCustomerId() == $data[&amp;#39;customer_id&amp;#39;] 97 ) { 98 return $order; 99 } 100 101 return null; 102} User input passed through the &amp;ldquo;data&amp;rdquo; request parameter is being base64-decoded and then JSON-decoded at line 85, and its &amp;ldquo;increment_id&amp;rdquo; and &amp;ldquo;customer_id&amp;rdquo; parameters are used to match the same values of the order object retrieved at line 93.</description>
    </item>
    
    <item>
      <title>Mantis Bug Tracker &lt;= 1.1.3 (utility_api.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-34/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-34/</guid>
      <description>Description: manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function() within the multi_sort() function in core/utility_api.php.
References:  CVE-2008-4687 BID-31789 EDB-6768  Disclosure Date: October 16, 2008</description>
    </item>
    
    <item>
      <title>Mantis Bug Tracker &lt;= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-18/</guid>
      <description>• Software Link: http://www.mantisbt.org
• Affected Versions: All versions from 1.2.0 to 1.2.17.
• Vulnerability Description: The vulnerable code is located in the /plugins/XmlImportExport/ImportXml.php script:
106printf( &amp;#34;Processing cross-references for %s issues...&amp;#34;, count( $importedIssues ) ); 107foreach( $importedIssues as $oldId =&amp;gt; $newId ) { 108 $bugData = bug_get( $newId, true ); 109 110 $bugLinkRegexp = &amp;#39;/(^|[^\w])(&amp;#39; . preg_quote( $this-&amp;gt;source_-&amp;gt;issuelink, &amp;#39;/&amp;#39; ) . &amp;#39;)(\d+)\b/e&amp;#39;; 111 $replacement = &amp;#39;&amp;#34;\\1&amp;#34; . $this-&amp;gt;getReplacementString( &amp;#34;\\2&amp;#34;, &amp;#34;\\3&amp;#34; )&amp;#39;; 112 113 $bugData-&amp;gt;description = preg_replace( $bugLinkRegexp, $replacement, $bugData-&amp;gt;description ); 114 $bugData-&amp;gt;update( true, true ); 115} User input passed through the &amp;ldquo;description&amp;rdquo; field (and the &amp;ldquo;issuelink&amp;rdquo; attribute) of the uploaded XML file when importing data through the Import/Export plugin is not properly sanitized before being used in a preg_replace() call with the e modifier at line 113.</description>
    </item>
    
    <item>
      <title>MercuryBoard &lt;= 1.1.5 (func/login.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-18/</guid>
      <description>Description: SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER[&amp;lsquo;HTTP_USER_AGENT&amp;rsquo;]).
References:  CVE-2008-6632 BID-29280 EDB-5653  Disclosure Date: May 19, 2008</description>
    </item>
    
    <item>
      <title>Nuke ET &lt;= 3.4 (FCKEditor) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-35/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-35/</guid>
      <description>Description: Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094.</description>
    </item>
    
    <item>
      <title>Open Journal Systems &lt;= 3.5.0-1 (NativeXmlIssueGalleyFilter.php) Path Traversal Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-11/</guid>
      <description>• Software Links: https://pkp.sfu.ca/software/ojs/
https://github.com/pkp/ojs
• Affected Versions: Version 3.3.0-21 and prior versions.
Version 3.4.0-9 and prior versions.
Version 3.5.0-1 and prior versions.
• Vulnerability Description: The vulnerability exists because user input passed to the &amp;ldquo;Native XML Plugin&amp;rdquo; through the issue -&amp;gt; issue_galleys -&amp;gt; issue_galley -&amp;gt; issue_file -&amp;gt; file_name tag of the imported XML file is not properly sanitized before being used to set the &amp;ldquo;server-side file name&amp;rdquo;, which is later used as the final part of a variable which is used at in a call to the writeFile() method without proper validation.</description>
    </item>
    
    <item>
      <title>Open Web Analytics &lt;= 1.5.6 (queue.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-03/</guid>
      <description>• Software Link: http://www.openwebanalytics.com
• Affected Versions: All versions from 1.2.2 to 1.5.6.
• Vulnerability Description: The vulnerable code is located in the /queue.php script:
40$owa-&amp;gt;setSetting(&amp;#39;base&amp;#39;, &amp;#39;is_remote_event_queue&amp;#39;, true); 41$owa-&amp;gt;e-&amp;gt;debug($_POST); 42$raw_event = owa_coreAPI::getRequestParam(&amp;#39;event&amp;#39;); 43 44if ( $raw_event ) { 45 46 $dispatch = owa_coreAPI::getEventDispatch(); 47 $event = unserialize( base64_decode( $raw_event ) ); 48 $owa-&amp;gt;e-&amp;gt;debug(print_r($event,true)); 49 $dispatch-&amp;gt;asyncNotify($event); 50} Input passed through the &amp;ldquo;owa_event&amp;rdquo; POST parameter is not properly sanitized before being used in a call to the unserialize() PHP function at line 47.</description>
    </item>
    
    <item>
      <title>OpenCart &lt;= 1.5.6.4 (cart.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-08/</guid>
      <description>• Software Link: http://www.opencart.com
• Affected Versions: Version 1.5.6.4 and prior versions.
• Vulnerability Description: The vulnerable code is located in the Cart::getProducts() method defined in /system/library/cart.php:
23foreach ($this-&amp;gt;session-&amp;gt;data[&amp;#39;cart&amp;#39;] as $key =&amp;gt; $quantity) { 24 $product = explode(&amp;#39;:&amp;#39;, $key); 25 $product_id = $product[0]; 26 $stock = true; 27 28 // Options 29 if (!empty($product[1])) { 30 $options = unserialize(base64_decode($product[1])); 31 } else { 32 $options = array(); 33 } The vulnerability exists because this method uses the unserialize() PHP function with the key values of the array stored into the &amp;ldquo;data[cart]&amp;quot; session variable without a proper validation.</description>
    </item>
    
    <item>
      <title>OpenConf &lt;= 4.11 (author/edit.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-82/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-82/</guid>
      <description>Description: OpenConf contains a flaw that may allow an attacker to carry out a blind SQL injection attack. The issue is due to the author/edit.php script not properly sanitizing user-supplied input passed via the &amp;lsquo;pid&amp;rsquo; POST parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data. Successful exploitation of this vulnerability requires at least a record into the paper table and the &amp;lsquo;Edit Submission&amp;rsquo; feature to be enabled.</description>
    </item>
    
    <item>
      <title>OpenPNE &lt;= 3.8.9 (opSecurityUser.class.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-01/</guid>
      <description>• Software Link: http://www.openpne.jp
• Affected Versions: All versions from 3.6.0 to 3.6.13.
All versions from 3.8.0 to 3.8.9.
• Vulnerability Description: The vulnerable code is located in the getRememberLoginCookie() method defined in /lib/user/opSecurityUser.class.php:
145protected function getRememberLoginCookie() 146{ 147 $key = md5(sfContext::getInstance()-&amp;gt;getRequest()-&amp;gt;getHost()); 148 if ($value = sfContext::getInstance()-&amp;gt;getRequest()-&amp;gt;getCookie($key)) 149 { 150 $value = unserialize(base64_decode($value)); 151 152 return $value; 153 } 154} User input passed through cookies is not properly sanitized before being used in an unserialize() call at line 150.</description>
    </item>
    
    <item>
      <title>openSIS &lt;= 5.2 (ajax.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-10/</guid>
      <description>• Software Link: http://www.opensis.com
• Affected Versions: All versions from 4.5 to 5.2.
• Vulnerability Description: The vulnerable code is located in the /ajax.php script:
86if(clean_param($_REQUEST[&amp;#39;modname&amp;#39;],PARAM_NOTAGS)) 87{ 88 if($_REQUEST[&amp;#39;_openSIS_PDF&amp;#39;]==&amp;#39;true&amp;#39;) 89 ob_start(); 90 if(strpos($_REQUEST[&amp;#39;modname&amp;#39;],&amp;#39;?&amp;#39;)!==false) 91 { 92 $vars = substr($_REQUEST[&amp;#39;modname&amp;#39;],(strpos($_REQUEST[&amp;#39;modname&amp;#39;],&amp;#39;?&amp;#39;)+1)); 93 $modname = substr($_REQUEST[&amp;#39;modname&amp;#39;],0,strpos($_REQUEST[&amp;#39;modname&amp;#39;],&amp;#39;?&amp;#39;)); 94 95 $vars = explode(&amp;#39;?&amp;#39;,$vars); 96 foreach($vars as $code) 97 { 98 $code = decode_unicode_url(&amp;#34;\$_REQUEST[&amp;#39;&amp;#34;.str_replace(&amp;#39;=&amp;#39;,&amp;#34;&amp;#39;]=&amp;#39;&amp;#34;,$code).&amp;#34;&amp;#39;;&amp;#34;); 99 eval($code); 100 } 101 } User input passed through the &amp;ldquo;modname&amp;rdquo; request variable is not properly sanitized before being used in an eval() call at line 99.</description>
    </item>
    
    <item>
      <title>openSIS &lt;= 7.4 (Bottom.php) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2020-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-07/</guid>
      <description>• Software Link: https://opensis.com
• Affected Versions: Version 7.4 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /Bottom.php script:
36if(clean_param($_REQUEST[&amp;#39;modfunc&amp;#39;],PARAM_ALPHA)==&amp;#39;print&amp;#39;) 37{ 38 $_REQUEST = $_SESSION[&amp;#39;_REQUEST_vars&amp;#39;]; 39 $_REQUEST[&amp;#39;_openSIS_PDF&amp;#39;] = true; 40 if(strpos($_REQUEST[&amp;#39;modname&amp;#39;],&amp;#39;?&amp;#39;)!==false) 41 $modname = substr($_REQUEST[&amp;#39;modname&amp;#39;],0,strpos($_REQUEST[&amp;#39;modname&amp;#39;],&amp;#39;?&amp;#39;)); 42 else 43 $modname = $_REQUEST[&amp;#39;modname&amp;#39;]; 44 ob_start(); 45 include(&amp;#39;modules/&amp;#39;.$modname); User input passed through the &amp;ldquo;modname&amp;rdquo; request parameter is not properly sanitized before being used in a call to the include() function at line 45.</description>
    </item>
    
    <item>
      <title>openSIS &lt;= 7.4 Incorrect Access Control Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2020-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-06/</guid>
      <description>• Software Link: https://opensis.com
• Affected Versions: Version 7.4 and prior versions.
• Vulnerabilities Description: The application prevents unauthenticated access to its functionalities by including the RedirectIncludes.php, RedirectModules.php, and RedirectRootInc.php scripts, which implement the access control logic by using the following code:
1if(!$_SESSION[&amp;#39;STAFF_ID&amp;#39;] &amp;amp;&amp;amp; !$_SESSION[&amp;#39;STUDENT_ID&amp;#39;] &amp;amp;&amp;amp; strpos($_SERVER[&amp;#39;PHP_SELF&amp;#39;],&amp;#39;index.php&amp;#39;)===false) 2{ 3 header(&amp;#39;Location: ../../../index.php&amp;#39;); 4 exit; 5} This can be easily bypassed by appending /index.php at the end of the URL, and can be exploited by unauthenticated attackers to potentially access any application functionality which should require the user to be authenticated.</description>
    </item>
    
    <item>
      <title>openSIS &lt;= 7.4 Multiple SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2020-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-08/</guid>
      <description>• Software Link: https://opensis.com
• Affected Versions: Version 7.4 and prior versions.
• Vulnerabilities Description: The application is affected by multiple SQL Injection vulnerabilities, following are some examples:
  User input passed through the api_key and api_secret parameters to /api/SchoolInfo.php, /api/StaffInfo.php, and /api/StudentEnrollmentInfo.php is not properly sanitized before being used to construct a SQL query. This can be exploited by unauthenticated attackers to e.g. read sensitive data from the database through error-based SQL Injection attacks.</description>
    </item>
    
    <item>
      <title>Oracle Application Express (AnyChart) Flash-based Cross-Site Scripting Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-01/</guid>
      <description>• Software Link: https://apex.oracle.com
• Affected Versions: All versions prior to 5.1.4.00.08.
• Vulnerability Description: The vulnerability is located in the OracleAnyChart.swf file. User input passed through the &amp;quot;__externalobjid&amp;quot; GET parameter is not properly sanitized before being passed to the ExternalInterface.call() method. This can be exploited to carry out reflected Cross-Site Scripting (XSS) attacks by tricking a victim user into opening an URL like the following:
• Solution: Update to version 5.</description>
    </item>
    
    <item>
      <title>Osclass &lt;= 3.4.2 (ajax.php) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-15/</guid>
      <description>• Software Link: http://osclass.org
• Affected Versions: Version 3.4.2 and probably prior versions.
• Vulnerability Description: The vulnerable code is located in the /oc-includes/osclass/controller/ajax.php script:
225case &amp;#39;custom&amp;#39;: // Execute via AJAX custom file 226 if(Params::existParam(&amp;#39;route&amp;#39;)) { 227 $routes = Rewrite::newInstance()-&amp;gt;getRoutes(); 228 $rid = Params::getParam(&amp;#39;route&amp;#39;); 229 $file = &amp;#39;../&amp;#39;; 230 if(isset($routes[$rid]) &amp;amp;&amp;amp; isset($routes[$rid][&amp;#39;file&amp;#39;])) { 231 $file = $routes[$rid][&amp;#39;file&amp;#39;]; 232 } 233 } else { 234 // DEPRECATED: Disclosed path in URL is deprecated, use routes instead 235 // This will be REMOVED in 3.</description>
    </item>
    
    <item>
      <title>Osclass &lt;= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-16/</guid>
      <description>• Software Link: http://osclass.org
• Affected Versions: Version 3.4.2 and probably prior versions.
• Vulnerability Description: The vulnerable code is located in the /oc-includes/osclass/controller/contact.php script:
97if( osc_contact_attachment() ) { 98 $attachment = Params::getFiles(&amp;#39;attachment&amp;#39;); 99 if(isset($attachment[&amp;#39;tmp_name&amp;#39;])) { 100 $resourceName = $attachment[&amp;#39;name&amp;#39;]; 101 $tmpName = $attachment[&amp;#39;tmp_name&amp;#39;]; 102 $resourceType = $attachment[&amp;#39;type&amp;#39;]; 103 $path = osc_uploads_path() . time() . &amp;#39;_&amp;#39; . $resourceName; 104 if( !is_writable(osc_uploads_path()) ) { 105 osc_add_flash_error_message( _m(&amp;#39;There have been some errors sending the message&amp;#39;)); 106 $this-&amp;gt;redirectTo( osc_contact_url() ); 107 } 108 109 if( !</description>
    </item>
    
    <item>
      <title>Osclass &lt;= 3.4.2 (Search::setJsonAlert) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-14/</guid>
      <description>• Software Link: http://osclass.org
• Affected Versions: Version 3.4.2 and probably prior versions.
• Vulnerability Description: The vulnerability exists because user input passed through the &amp;ldquo;alert&amp;rdquo; parameter when subscribing to a search alert is not properly validated before being stored into the DB (s_search field of the oc_t_alerts table). This can be exploited by unauthenticated attackers to inject arbitrary SQL commands via several parameters passed to the Search::setJsonAlert() method, which are later used to make a SQL query within the Search::doSearch() method.</description>
    </item>
    
    <item>
      <title>PEAR HTML_AJAX &lt;= 0.5.7 (PHP Serializer) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2017-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2017-01/</guid>
      <description>• Software Link: https://pear.php.net/package/HTML_AJAX
• Affected Versions: All versions from 0.3.0 to 0.5.7.
• Vulnerability Description: The vulnerable code is located within the HTML_AJAX_Serializer_PHP class defined into the /AJAX/Serializer/PHP.php script. Such a class uses the unserialize() PHP function with user-controlled input unless a class name which is not in the provided array of allowed classes is found within the serialized string. Class names are extracted by using the _getSerializedClassNames() method:</description>
    </item>
    
    <item>
      <title>PHP iCalendar &lt;= 2.24 Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-27/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-27/</guid>
      <description>Description: admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.
References:  CVE-2008-5967 EDB-6519  Disclosure Date: September 21, 2008</description>
    </item>
    
    <item>
      <title>Php-Stats 0.1.9.2 (php-stats.recjs.php) Multiple SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/vuln-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-3/</guid>
      <description>Description: Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) ip or (2) t parameter.
References:  CVE-2007-5452 BID-26022 EDB-4513  Disclosure Date: October 10, 2007</description>
    </item>
    
    <item>
      <title>Php-Stats 0.1.9.2 Multiple PHP Code Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/vuln-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-2/</guid>
      <description>Description: Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by (1) admin.php, (2) click.php, (3) download.php, and unspecified other files, as demonstrated by modifying _options through a backup restore action in admin.php.
References:  CVE-2007-5453 BID-26022 EDB-4513  Disclosure Date: October 10, 2007</description>
    </item>
    
    <item>
      <title>phpFox &lt;= 3.0.1 (module.class.php) OS Command Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-79/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-79/</guid>
      <description>Description: phpFox contains a flaw related to the Phpfox_Module::getComponent() method defined in the module.class.php script which not properly sanitize input passed via the &amp;lsquo;phpfox[call]&amp;rsquo; or &amp;lsquo;core[call]&amp;rsquo; parameters before using it in an eval() call. This may allow an attacker to inject and execute arbitrary OS commands.
References:  CVE-2012-1300 BID-52699 EDB-18655 http://www.phpfox.com/blog/v2-1-0-build-3-v3-0-1-build-3-released/  Disclosure Date: March 23, 2012</description>
    </item>
    
    <item>
      <title>phpFox &lt;= 4.8.13 (redirect) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-12/</guid>
      <description>• Software Link: https://www.phpfox.com
• Affected Versions: Version 4.8.13 and prior versions.
• Vulnerability Description: User input passed through the &amp;ldquo;url&amp;rdquo; request parameter to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.</description>
    </item>
    
    <item>
      <title>PHPizabi v0.848b (file.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-36/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-36/</guid>
      <description>Description: PHPizabi is prone to a vulnerability that lets remote attackers to upload and execute arbitrary PHP code. The vulnerability is caused due to an error in the handling of file uploads in the modules/interact/file.php script.
References:  BID-34255 EDB-8287  Disclosure Date: March 25, 2009</description>
    </item>
    
    <item>
      <title>phpLDAPadmin &lt;= 1.2.1.1 (lib/functions.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-53/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-53/</guid>
      <description>Description: phpLDAPadmin contains a flaw related to the lib/functions.php script which fails to properly sanitize user-supplied input passed to the cmd.php script via the &amp;lsquo;orderby&amp;rsquo; parameter before use it in a call to the create_function() PHP function. This allows a remote attacker to inject and execute arbitrary PHP code.
References:  CVE-2011-4075 BID-50331 EDB-18021  Disclosure Date: October 23, 2011</description>
    </item>
    
    <item>
      <title>PHPmotion &lt;= 2.0 (play.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-22/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-22/</guid>
      <description>Description: SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.
References:  CVE-2008-3118 BID-29949 EDB-5938  Disclosure Date: June 25, 2008</description>
    </item>
    
    <item>
      <title>PHPmotion &lt;= 2.0 (update_profile.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-23/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-23/</guid>
      <description>Description: Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/.
References:  CVE-2008-3117 BID-29949 EDB-5938  Disclosure Date: June 25, 2008</description>
    </item>
    
    <item>
      <title>phpMyFAQ &lt;= 2.7.0 (ajax_create_folder.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-63/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-63/</guid>
      <description>Description: Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References:  CVE-2011-4825 BID-50523 EDB-18084 http://www.phpmyfaq.de/advisory_2011-10-25.php  Disclosure Date: November 5, 2011</description>
    </item>
    
    <item>
      <title>phpScheduleIt &lt;= 1.2.10 Multiple PHP Code Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/vuln-30/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-30/</guid>
      <description>Description: Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter.
References:  CVE-2008-6132 BID-31520 EDB-6646  Disclosure Date: October 1, 2008</description>
    </item>
    
    <item>
      <title>phpScheduleIt &lt;= 1.2.11 (check.php) Multiple PHP Code Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/vuln-31/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-31/</guid>
      <description>Description: Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.
References:  CVE-2009-0820 EDB-6646  Disclosure Date: October 1, 2008</description>
    </item>
    
    <item>
      <title>PhpWebGallery &lt;= 1.7.2 (comments.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-33/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-33/</guid>
      <description>Description: PhpWebGallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the &amp;lsquo;comments.php&amp;rsquo; script not properly sanitizing user-supplied input to the &amp;lsquo;sort_by&amp;rsquo; variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
References:  BID-31762 EDB-6755  Disclosure Date: October 14, 2008</description>
    </item>
    
    <item>
      <title>PhpWebGallery &lt;= 1.7.2 (event_list.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-32/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-32/</guid>
      <description>Description: plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function().
References:  CVE-2008-4645 BID-31762 EDB-6755  Disclosure Date: October 14, 2008</description>
    </item>
    
    <item>
      <title>Piwik &lt;= 2.14.3 (DisplayTopKeywords) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-10/</guid>
      <description>• Software Link: https://piwik.org
• Affected Versions: Version 2.14.3 and prior versions.
• Vulnerability Description: The vulnerability is caused by the DisplayTopKeywords() method defined in the /plugins/Referrers/Controller.php script:
358function DisplayTopKeywords($url = &amp;#34;&amp;#34;, $api) 359{ 360 // Do not spend more than 1 second fetching the data 361 @ini_set(&amp;#34;default_socket_timeout&amp;#34;, $timeout = 1); 362 // Get the Keywords data 363 $url = empty($url) ? &amp;#34;http://&amp;#34; . $_SERVER[&amp;#34;HTTP_HOST&amp;#34;] . $_SERVER[&amp;#34;REQUEST_URI&amp;#34;] : $url; 364 $api = $api .</description>
    </item>
    
    <item>
      <title>Piwik &lt;= 2.14.3 (viewDataTable) Autoloaded File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2015-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2015-09/</guid>
      <description>• Software Link: https://piwik.org
• Affected Versions: Version 2.14.3 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /core/ViewDataTable/Factory.php script:
130 $type = Common::getRequestVar(&amp;#39;viewDataTable&amp;#39;, $defaultType, &amp;#39;string&amp;#39;); 131 132 // Common::getRequestVar removes backslashes from the defaultValue in case magic quotes are enabled. 133 // therefore do not pass this as a default value to getRequestVar() 134 if (&amp;#39;&amp;#39; === $type) { 135 $type = $defaultType ?: HtmlTable::ID; 136 } 137} else { 138 $type = $defaultViewType; 139} 140 141$params[&amp;#39;viewDataTable&amp;#39;] = $type; 142 143$visualizations = Manager::getAvailableViewDataTables(); 144 145if (array_key_exists($type, $visualizations)) { 146 return self::createViewDataTableInstance($visualizations[$type], $controllerAction, $apiAction, $params); 147} 148 149if (class_exists($type)) { User input passed through the &amp;ldquo;viewDataTable&amp;rdquo; request parameter is not properly sanitized before being used in a call to the class_exists() PHP function at line 149.</description>
    </item>
    
    <item>
      <title>Piwik &lt;= 2.16.0 (saveLayout) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-13/</guid>
      <description>• Software Link: https://piwik.org
• Affected Versions: Version 2.16.0 and prior versions.
• Vulnerability Description: The vulnerability can be triggered through the saveLayout() method defined into the /plugins/Dashboard/Controller.php script:
210public function saveLayout() 211{ 212 $this-&amp;gt;checkTokenInUrl(); 213 214 $layout = Common::unsanitizeInputValue(Common::getRequestVar(&amp;#39;layout&amp;#39;)); 215 $layout = strip_tags($layout); 216 $idDashboard = Common::getRequestVar(&amp;#39;idDashboard&amp;#39;, 1, &amp;#39;int&amp;#39;); 217 $name = Common::getRequestVar(&amp;#39;name&amp;#39;, &amp;#39;&amp;#39;, &amp;#39;string&amp;#39;); 218 219 if (Piwik::isUserIsAnonymous()) { 220 $session = new SessionNamespace(&amp;#34;Dashboard&amp;#34;); 221 $session-&amp;gt;dashboardLayout = $layout; 222 $session-&amp;gt;setExpirationSeconds(1800); User input passed by anonymous users through the &amp;ldquo;layout&amp;rdquo; request parameter is being stored into a session variable at line 221, and this is possible by invoking an URL like this:</description>
    </item>
    
    <item>
      <title>PKP-WAL &lt;= 3.4.0-3 (NativeImportExportPlugin) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-14/</guid>
      <description>• Software Links: https://pkp.sfu.ca
https://github.com/pkp/pkp-lib
• Affected Versions: PKP Web Application Library (aka PKP-WAL or pkp-lib) version 3.4.0-3 and prior versions, as used in Open Journal Systems (OJS), Open Monograph Press (OMP), and Open Preprint Systems (OPS) before versions 3.4.0-4 or 3.3.0-16.
• Vulnerability Description: The vulnerability is located in the /plugins/importexport/native/filter/PKPNativeFilterHelper.php script.
Specifically, into the PKPNativeFilterHelper::parsePublicationCover() method:
100 public function parsePublicationCover($filter, $node, $object) 101 { 102 $deployment = $filter-&amp;gt;getDeployment(); 103 104 $context = $deployment-&amp;gt;getContext(); 105 106 $locale = $node-&amp;gt;getAttribute(&amp;#39;locale&amp;#39;); 107 if (empty($locale)) { 108 $locale = $context-&amp;gt;getPrimaryLocale(); 109 } 110 111 $coverImagelocale = []; 112 $coverImage = []; 113 114 for ($n = $node-&amp;gt;firstChild; $n !</description>
    </item>
    
    <item>
      <title>PKP-WAL &lt;= 3.5.0-1 (baseColour) LESS Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-12/</guid>
      <description>• Software Links: https://pkp.sfu.ca
https://github.com/pkp/pkp-lib
• Affected Versions: PKP Web Application Library (aka PKP-WAL or pkp-lib) version 3.4.0-9 and prior versions, and version 3.5.0-1 and prior versions, as used in Open Journal Systems (OJS), Open Monograph Press (OMP), and Open Preprint Systems (OPS).
• Vulnerability Description: The vulnerability exists within the PKPTemplateManager::compileLess() method. This will call the Less_Parser::parse() method by using the &amp;ldquo;addLessVariables&amp;rdquo;, which can be manipulated when updating &amp;ldquo;Theme Settings&amp;rdquo;.</description>
    </item>
    
    <item>
      <title>PKP-WAL &lt;= 3.5.0-1 (Institution Collector) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-10/</guid>
      <description>• Software Links: https://pkp.sfu.ca
https://github.com/pkp/pkp-lib
• Affected Versions: PKP Web Application Library (aka PKP-WAL or pkp-lib) version 3.4.0-9 and prior versions, and version 3.5.0-1 and prior versions, as used in Open Journal Systems (OJS), Open Monograph Press (OMP), and Open Preprint Systems (OPS).
• Vulnerability Description: The vulnerability is located in the /classes/institution/Collector.php script.
Specifically, into the Collector::getQueryBuilder() method:
121 public function getQueryBuilder(): Builder 122 { 123 $qb = DB::table($this-&amp;gt;dao-&amp;gt;table .</description>
    </item>
    
    <item>
      <title>PKP-WAL &lt;= 3.5.0-1 Login Cross-Site Request Forgery Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-14/</guid>
      <description>• Software Links: https://pkp.sfu.ca
https://github.com/pkp/pkp-lib
• Affected Versions: Version 3.3.0-21 and prior versions.
Version 3.4.0-9 and prior versions.
Version 3.5.0-1 and prior versions.
• Vulnerability Description: Open Journal Systems (OJS), Open Monograph Press (OMP), and Open Preprint Systems (OPS) allow users to perform a login without providing the &amp;ldquo;csrfToken&amp;rdquo; parameter, which is included on the client-side, but it&amp;rsquo;s not validated on the server-side. As such, all these applications are vulnerable to potential &amp;ldquo;Login Cross-Site Request Forgery&amp;rdquo; attacks.</description>
    </item>
    
    <item>
      <title>PKP-WAL &lt;= 3.5.0-3 (X-Forwarded-Host) LESS Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-13/</guid>
      <description>• Software Links: https://pkp.sfu.ca
https://github.com/pkp/pkp-lib
• Affected Versions: PKP Web Application Library (aka PKP-WAL or pkp-lib) version 3.4.0-10 and prior versions, and version 3.5.0-3 and prior versions, as used in Open Journal Systems (OJS), Open Monograph Press (OMP), and Open Preprint Systems (OPS).
• Vulnerability Description: The vulnerability exists within the PKPTemplateManager::compileLess() method, which will call the Less_Parser::parse() method passing to it the &amp;ldquo;baseUrl&amp;rdquo; variable. Such a variable, which is constructed from a call to the $request-&amp;gt;getBaseUrl() method, can be manipulated by unauthenticated attackers through the X-Forwarded-Host HTTP header, and this can be exploited to perform LESS Code Injection attacks, subsequently leading to SSRF or Local File Read attacks.</description>
    </item>
    
    <item>
      <title>PMOS Help Desk &lt;= 2.4 (form.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-5/</guid>
      <description>Description: form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
References:  CVE-2007-6550 BID-27032 EDB-4789  Disclosure Date: December 25, 2007</description>
    </item>
    
    <item>
      <title>PmWiki &lt;= 2.2.34 (pagelist.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-69/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-69/</guid>
      <description>Description: PmWiki contains a vulnerability that allows a remote attacker to inject and execute arbitrary PHP code. The PageListSort() function defined in the scripts/pagelist.php script allows to inject arbitrary PHP code in a call to the create_function() PHP function via a crafted &amp;lsquo;order&amp;rsquo; parameter of a pagelist directive.
References:  CVE-2011-4453 BID-50776 EDB-18149 http://www.pmwiki.org/wiki/PmWiki/ChangeLog#v2235  Disclosure Date: November 23, 2011</description>
    </item>
    
    <item>
      <title>qdPM &lt;= 9.1 (executeExport) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2020-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-11/</guid>
      <description>• Software Link: http://qdpm.net
• Affected Versions: Version 9.1 and prior versions.
• Vulnerability Description: The vulnerability is located in the /core/apps/qdPM/modules/timeReport/actions/actions.class.php script, specifically within the timeReportActions::executeExport() method:
295public function executeExport(sfWebRequest $request) 296{ 297 $separator = &amp;#34;\t&amp;#34;; 298 $format = $request-&amp;gt;getParameter(&amp;#39;format&amp;#39;); 299 $filename = $request-&amp;gt;getParameter(&amp;#39;filename&amp;#39;); 300 301 $export = unserialize($request-&amp;gt;getParameter(&amp;#39;export&amp;#39;)); User input passed through the &amp;ldquo;export&amp;rdquo; request parameter is not properly sanitized before being used in a call to the unserialize() function at line 301.</description>
    </item>
    
    <item>
      <title>QuiXplorer &lt;= 2.3.2 (init.php) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-42/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-42/</guid>
      <description>Description: Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
References:  CVE-2009-1911 BID-34892 EDB-8649  Disclosure Date: May 8, 2009</description>
    </item>
    
    <item>
      <title>Research</title>
      <link>https://karmainsecurity.com/research/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/research/</guid>
      <description>- 2025       PKP-WAL &amp;lt;= 3.5.0-1 Login Cross-Site Request Forgery Vulnerability    PKP-WAL &amp;lt;= 3.5.0-3 (X-Forwarded-Host) LESS Code Injection Vulnerability    PKP-WAL &amp;lt;= 3.5.0-1 (baseColour) LESS Code Injection Vulnerability    Open Journal Systems &amp;lt;= 3.5.0-1 (NativeXmlIssueGalleyFilter.php) Path Traversal Vulnerability    PKP-WAL &amp;lt;= 3.5.0-1 (Institution Collector) SQL Injection Vulnerability    Control Web Panel &amp;lt;= 0.</description>
    </item>
    
    <item>
      <title>RoSPORA &lt;= 1.5.0 (index.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-43/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-43/</guid>
      <description>Description: RoSPORA contains a flaw that allows malicious users to inject and execute arbitrary PHP code. The issue is due to user-supplied input passed through the $_GET[&amp;rsquo;s&#39;] parameter isn&amp;rsquo;t properly sanitized before being used in a call to the create_function() PHP function into the index.php script.
References:  BID-44554 EDB-15343  Disclosure Date: October 28, 2010</description>
    </item>
    
    <item>
      <title>Seagull PHP Framework &lt;= 0.6.4 Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-24/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-24/</guid>
      <description>Description: Seagull PHP Framework contains a flaw that allows a remote user to execute arbitrary PHP code. The vulnerability is caused due to an error in the handling of file uploads in the tinyfck/filemanager/connectors/php/connector.php script, when a file name has multiple file extensions. This can be exploited to upload malicious PHP scripts.
References:  BID-29982 EDB-5945  Disclosure Date: June 26, 2008</description>
    </item>
    
    <item>
      <title>Sharetronix &lt;= 3.1.1 (AJAX Services) Authentication Bypass Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-15/</guid>
      <description>• Software Link: http://sharetronix.com
• Affected Versions: Version 3.1.1 and probably other versions.
• Vulnerability Description: The application does not properly restrict access to certain AJAX functionalities. This can be exploited to bypass the authentication mechanism and access such functionalities without valid credentials.
• Solution: No official solution is currently available.
• Disclosure Timeline: [06/11/2013] – Vendor notified
[06/11/2013] – Vendor response stating “Please immediately cease and desist all such communications”</description>
    </item>
    
    <item>
      <title>Sharetronix &lt;= 3.1.1 (attachments.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-12/</guid>
      <description>• Software Link: http://sharetronix.com
• Affected Versions: Version 3.1.1 and probably other versions.
• Vulnerability Description: An error due to the /system/controllers/ajax/attachments.php script not properly validating the extension of an uploaded file can be exploited to execute arbitrary PHP code by uploading a malicious PHP file.
• Solution: No official solution is currently available.
• Disclosure Timeline: [06/11/2013] – Vendor notified
[06/11/2013] – Vendor response stating “Please immediately cease and desist all such communications”</description>
    </item>
    
    <item>
      <title>Sharetronix &lt;= 3.1.1 (signup.php) Two SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2013-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-13/</guid>
      <description>• Software Link: http://sharetronix.com
• Affected Versions: Version 3.1.1 and probably other versions.
• Vulnerabilities Description: Input passed via the &amp;ldquo;fb_user_id&amp;rdquo; and &amp;ldquo;tw_user_id&amp;rdquo; parameters to /signup is not properly sanitised before being used in a SQL query in the /system/controllers/signup.php script. This can be exploited to conduct SQL injection and privilege escalation attacks.
• Solution: No official solution is currently available.
• Disclosure Timeline: [06/11/2013] – Vendor notified
[06/11/2013] – Vendor response stating “Please immediately cease and desist all such communications”</description>
    </item>
    
    <item>
      <title>Sharetronix &lt;= 3.1.1 Cross-Site Request Forgery Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-14/</guid>
      <description>• Software Link: http://sharetronix.com
• Affected Versions: Version 3.1.1 and probably other versions.
• Vulnerability Description: The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. change certain configuration settings or create a user with administrative privileges by tricking a logged in administrator into visiting a malicious web site.
• Solution: No official solution is currently available.</description>
    </item>
    
    <item>
      <title>Sharetronix &lt;= 3.1.1 Two PHP Code Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2013-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-11/</guid>
      <description>• Software Link: http://sharetronix.com
• Affected Versions: Version 3.1.1 and probably other versions.
• Vulnerabilities Description:   Input passed via the &amp;ldquo;activities_text&amp;rdquo; POST parameter to /services/activities/set is not properly sanitised before being used in a call to the preg_replace() PHP function with the e modifier in the /system/classes/class_post.php script. This can be exploited to inject and execute arbitrary PHP code.
  Input passed via the &amp;ldquo;comments_text&amp;rdquo; POST parameter to /services/comments/set is not properly sanitised before being used in a call to the preg_replace() PHP function with the e modifier in the /system/classes/class_postcomment.</description>
    </item>
    
    <item>
      <title>Site@School &lt;= 2.3.10 (slideshow_full.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-9/</guid>
      <description>Description: SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.
References:  CVE-2008-0129 BID-27120 EDB-4832  Disclosure Date: January 3, 2008</description>
    </item>
    
    <item>
      <title>SugarCRM (addLabels) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-06/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0.
• Vulnerability Description: User input passed through key values of the &amp;ldquo;labels_&amp;quot; parameters is not properly sanitized before being used to save PHP code within the ParserLabel::addLabels() method when saving labels through the Module Builder. This can be exploited to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires admin privileges.
• Solution: Update to versions 7.</description>
    </item>
    
    <item>
      <title>SugarCRM (ConnectorsController) Server-Side Request Forgery Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-04/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.4.0 and 7.11.0.0.
• Vulnerability Description: The vulnerability is located within the ConnectorsController::action_CallRest() method. User input passed through the &amp;ldquo;url&amp;rdquo; request parameter is not properly sanitized before being used in a call to the file_get_contents() PHP function. This can be exploited to carry out Server-Side Request Forgery (SSRF) and Reflected Cross-Site Scripting (XSS) attacks.
• Solution: Update to versions 7.</description>
    </item>
    
    <item>
      <title>SugarCRM (portal_get_related_notes) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-03/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.4.0 and 7.11.0.0.
• Vulnerability Description: The vulnerability is located within the SOAP API, specifically into the portal_get_related_notes() SOAP function. User input passed through the &amp;ldquo;order_by&amp;rdquo; parameter isn’t properly sanitized before being used to construct an “ORDER BY” clause of a SQL query from within the get_notes_in_contacts() or get_notes_in_module() functions. This can be exploited by Portal API Users to e.</description>
    </item>
    
    <item>
      <title>SugarCRM (SaveDropDown) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-05/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0.
• Vulnerability Description: User input passed through key values of the &amp;ldquo;list_value&amp;rdquo; JSON parameter is not properly sanitized before being used to save PHP code when adding/saving dropdowns through the Module Builder. This can be exploited to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires admin privileges.
• Solution: Update to versions 7.</description>
    </item>
    
    <item>
      <title>SugarCRM (Web Logic Hooks module) Path Traversal Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-08/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0.
• Vulnerability Description: User input passed through the &amp;ldquo;webhook_target_module&amp;rdquo; parameter is not properly sanitized before being used to save PHP code into the hooks file through the Web Logic Hooks module. This can be exploited to carry out Path Traversal attacks and e.g. create arbitrary directories. Successful exploitation of this vulnerability requires admin privileges.
• Solution: Update to versions 7.</description>
    </item>
    
    <item>
      <title>SugarCRM (Web Logic Hooks module) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-07/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0.
• Vulnerability Description: User input passed through the &amp;ldquo;trigger_event&amp;rdquo; parameter is not properly sanitized before being used to save PHP code into the logic_hooks.php file through the Web Logic Hooks module. This can be exploited to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires admin privileges.
• Solution: Update to versions 7.</description>
    </item>
    
    <item>
      <title>SugarCRM (WorkFlow module) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2018-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2018-02/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: All versions prior to 7.9.4.0 and 7.11.0.0.
• Vulnerability Description: User input passed through the $_POST[&amp;lsquo;base_module&amp;rsquo;] parameter to the &amp;ldquo;Save&amp;rdquo; action of the WorkFlow module is not properly sanitized before being used to write data into the workflow.php file. This can be exploited to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires admin privileges.
• Solution: Update to versions 7.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt; 10.1.0 (Reports Export) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2020-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-10/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: All versions prior to 10.1.0 (Q3 2020).
• Vulnerability Description: User input passed through the encoded &amp;ldquo;current_post&amp;rdquo; parameter to index.php (when &amp;ldquo;entryPoint&amp;rdquo; is set to &amp;ldquo;export&amp;rdquo; and &amp;ldquo;module&amp;rdquo; is set to &amp;ldquo;Reports&amp;rdquo;) is not properly sanitized before being used to construct a SQL query. This can be exploited by remote attackers to e.g. read sensitive data from the database through e.g. time-based SQL Injection attacks.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt; 10.1.0 Multiple Reflected Cross-Site Scripting Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2020-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-09/</guid>
      <description>• Software Link: https://www.sugarcrm.com/
• Affected Versions: All versions prior to 10.1.0 (Q3 2020).
• Vulnerabilities Description:  User input passed through the “do” parameter when action is set to “metadata” is not properly sanitized before being used to generate HTML output. This can be exploited by malicious users to carry out Reflected Cross-Site Scripting (XSS) attacks.  Proof of Concept 1: https://[HOST]/index.php?action=metadata&amp;amp;do=%27);alert(%27XSS%27)// User input passed through the “current_step” parameter to the “Reports” module is not properly sanitized before being used to generate HTML output.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 12.2.0 (Docusign_GlobalSettings) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-07/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 12.2.0 and prior versions.
Version 12.0.2 and prior versions.
Version 11.0.5 and prior versions.
• Vulnerability Description: There is a Second-Order PHP Object Injection vulnerability which might allow malicious admin users to execute arbitrary PHP code on the web server (RCE) by storing malicious serialized objects into the database.
The vulnerability can be triggered by invoking the &amp;quot;/DocuSign/getGlobalConfig&amp;quot; REST API endpoint, which is using the unserialize() PHP function with the &amp;ldquo;Docusign_GlobalSettings&amp;rdquo; parameter.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 12.2.0 (Notes) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-05/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 12.2.0 and prior versions.
Version 12.0.2 and prior versions.
Version 11.0.5 and prior versions.
• Vulnerability Description: When handling the &amp;ldquo;save&amp;rdquo; action within the &amp;ldquo;Notes&amp;rdquo; module the application allows uploading of any kind of file into the /upload/ directory. This one is protected by the main SugarCRM .htaccess file, i.e. it doesn’t allow access/execution for PHP files. However, this behaviour can be overridden if a subdirectory contains another .</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 12.2.0 (updateGeocodeStatus) Bean Manipulation Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-06/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 12.2.0 and prior versions.
Version 12.0.2 and prior versions.
Version 11.0.5 and prior versions.
• Vulnerability Description: The vulnerability is exploitable through the &amp;quot;/maps/updateGeocodeStatus&amp;quot; REST API endpoint. This might allow a malicious user to modify arbitrary Sugar Beans, and that could lead to a variety of security impacts, such as Privilege Escalation attacks by sending an HTTP request like the following:
POST /rest/v11_17/maps/updateGeocodeStatus HTTP/1.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 12.2.0 Two SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2023-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-08/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 12.2.0 and prior versions.
Version 12.0.2 and prior versions.
Version 11.0.5 and prior versions.
• Vulnerabilities Description:   User input passed through the &amp;ldquo;metrics&amp;rdquo; parameter to the &amp;quot;/Forecasts/metrics&amp;quot; REST API endpoint is not properly sanitized before being used to construct a SQL query. This can be exploited by malicious users to e.g. read sensitive data from the database through in-band SQL Injection attacks.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 13.0.1 (GetControl) Server-Side Template Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-10/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 13.0.1 and prior versions.
Version 12.0.3 and prior versions.
• Vulnerability Description: There is a sort of Server-Side Template Injection (SSTI) vulnerability affecting the &amp;ldquo;GetControl&amp;rdquo; action from the &amp;ldquo;Import&amp;rdquo; module. User input passed through the &amp;ldquo;field_name&amp;rdquo; parameter is not properly sanitized before being used to construct the path of the template to include. As such, this can be abused to include and execute arbitrary PHP code through Path Traversal attacks.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 13.0.1 (set_note_attachment) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-11/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 13.0.1 and prior versions.
Version 12.0.3 and prior versions.
• Vulnerability Description: When handling the set_note_attachment SOAP call, the application allows uploading of any kind of file into /upload/ directory. This one is protected by the main SugarCRM .htaccess file, i.e. it doesn’t allow access/execution of PHP files. However, this behavior can be overridden if the subdirectory contains another .htaccess file. So, an attacker can leverage the vulnerability to firstly upload a new .</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 14.0.0 (css/preview) LESS Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-04/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: All commercial versions before 13.0.4 and 14.0.1.
• Vulnerability Description: User input passed through GET parameters to the /css/preview REST API endpoint is not properly sanitized before parsing it as LESS code. This can be exploited by remote, unauthenticated attackers to inject and execute arbitrary LESS directives. By abusing the @import LESS statement, an attacker can trigger Server-Side Request Forgery (SSRF) or read arbitrary local files on the web server, potentially leading to the disclosure of sensitive information.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 6.3.1 Multiple PHP Object Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/vuln-83/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-83/</guid>
      <description>Description: SugarCRM contains a flaw that is triggered when certain scripts fail to properly sanitize user-supplied input before being used in an unserialize() call. With a specially crafted serialized object an attacker might be able to create a cache file containing arbitrary PHP code abusing the __destruct() method of the SugarTheme class.
References:  CVE-2012-0694 BID-54169 EDB-19381  Disclosure Date: June 23, 2012</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 6.5.18 (MySugar::addDashlet) Insecure fopen() Usage Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-06/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: Version 6.5.18 CE and other versions.
• Vulnerability Description: The vulnerable code is located within the MySugar::addDashlet() method:
89if (isset($_REQUEST[&amp;#39;type&amp;#39;]) &amp;amp;&amp;amp; $_REQUEST[&amp;#39;type&amp;#39;] == &amp;#39;web&amp;#39;) { 90 $dashlet_module = &amp;#39;Home&amp;#39;; 91 require_once(&amp;#39;include/Dashlets/DashletRssFeedTitle.php&amp;#39;); 92 $options[&amp;#39;url&amp;#39;] = $_REQUEST[&amp;#39;type_module&amp;#39;]; 93 $webDashlet = new DashletRssFeedTitle($options[&amp;#39;url&amp;#39;]); 94 $options[&amp;#39;title&amp;#39;] = $webDashlet-&amp;gt;generateTitle(); User input passed through the &amp;ldquo;type_module&amp;rdquo; request parameter isn’t properly sanitized before being used to instantiate a new DashletRssFeedTitle object, and this could be exploited to carry out certain attacks because of the DashletRssFeedTitle::readFeed() method (user input passed directly to the fopen() PHP function):</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 6.5.18 (SAML Authentication) XML External Entity Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-03/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: Version 6.5.18 CE and prior versions.
• Vulnerability Description: The vulnerable code is located in the constructor method of the SamlResponse class:
63function __construct($settings, $assertion) { 64 $this-&amp;gt;settings = $settings; 65 $this-&amp;gt;assertion = base64_decode($assertion); 66 $this-&amp;gt;xml = new DOMDocument(); 67 $this-&amp;gt;xml-&amp;gt;loadXML($this-&amp;gt;assertion); 68} Which is being called by the authenticateUser method of the SAMLAuthenticateUser class:
75$samlresponse = new SamlResponse($settings, $_POST[&amp;#39;SAMLResponse&amp;#39;]); User input passed through the &amp;ldquo;SAMLResponse&amp;rdquo; POST parameter isn’t properly sanitized before being used in a call to the DOMDocument::loadXML() method, and there are no calls to the libxml_disable_entity_loader() function.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 6.5.18 Missing Authorization Check Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2016-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-04/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: Version 6.5.18 CE and prior versions.
• Vulnerabilities Description: The application fails to properly check whether the user has administrator privileges within the following scripts:
 /modules/Administration/ImportCustomFieldStructure.php /modules/Administration/UpgradeWizard_commit.php /modules/Connectors/controller.php (&amp;ldquo;RunTest&amp;rdquo; action)  This can be exploited by authenticated users to access certain otherwise restricted administrative features or exploit further vulnerabilities within the affected scripts (e.g. a SQL injection vulnerability located within the ImportCustomFieldStructure.php file).</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 6.5.18 Two PHP Code Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2016-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-05/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: Version 6.5.18 CE and prior versions.
• Vulnerabilities Description:  The vulnerable code is located in the /include/utils/array_utils.php script:  99function override_value_to_string_recursive2($array_name, $value_name, $value, $save_empty = true) { 100 if (is_array($value)) { 101 $str = &amp;#39;&amp;#39;; 102 $newArrayName = $array_name . &amp;#34;[&amp;#39;$value_name&amp;#39;]&amp;#34;; 103 foreach($value as $key=&amp;gt;$val) { 104 $str.= override_value_to_string_recursive2($newArrayName, $key, $val, $save_empty); 105 } 106 return $str; 107 } else { 108 if(!</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 6.5.23 (SugarRestSerialize.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-07/</guid>
      <description>• Software Link: http://www.sugarcrm.com
• Affected Versions: Version 6.5.23 CE and prior versions.
• Vulnerability Description: The vulnerable code is located in the /service/core/REST/SugarRestSerialize.php script:
67function serve(){ 68 $GLOBALS[&amp;#39;log&amp;#39;]-&amp;gt;info(&amp;#39;Begin: SugarRestSerialize-&amp;gt;serve&amp;#39;); 69 $data = !empty($_REQUEST[&amp;#39;rest_data&amp;#39;])? $_REQUEST[&amp;#39;rest_data&amp;#39;]: &amp;#39;&amp;#39;; 70 if(empty($_REQUEST[&amp;#39;method&amp;#39;]) || !method_exists($this-&amp;gt;implementation, $_REQUEST[&amp;#39;method&amp;#39;])){ 71 $er = new SoapError(); 72 $er-&amp;gt;set_error(&amp;#39;invalid_call&amp;#39;); 73 $this-&amp;gt;fault($er); 74 }else{ 75 $method = $_REQUEST[&amp;#39;method&amp;#39;]; 76 $data = unserialize(from_html($data)); 77 if(!is_array($data))$data = array($data); 78 $GLOBALS[&amp;#39;log&amp;#39;]-&amp;gt;info(&amp;#39;End: SugarRestSerialize-&amp;gt;serve&amp;#39;); User input passed through the &amp;ldquo;rest_data&amp;rdquo; request parameter is not properly sanitized before being used in a call to the unserialize() PHP function at line 76.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple Broken Access Control Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-05/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   There is a Broken Access Control vulnerability with regards to the &amp;ldquo;InboundEmail&amp;rdquo; module. When handling the &amp;ldquo;Save&amp;rdquo; action the application fails to properly check whether the user has Admin access to the module, thus allowing any user to create a new &amp;ldquo;InboundEmail&amp;rdquo; bean regardless of their roles/permissions.
  There is a Broken Access Control vulnerability with regards to the &amp;ldquo;Trackers&amp;rdquo; module.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple Path Traversal Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-06/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   User input passed to the &amp;quot;/Mail/attachment&amp;quot; REST API endpoint is not properly sanitized before being used to delete a file from the system. This can be exploited by malicious users to delete arbitrary files via Path Traversal attacks. Please note this vulnerability could be exploited to delete the config.php file and re-install the application, potentially leading to a full server compromise.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple Phar Deserialization Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-09/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   User input passed through the &amp;ldquo;backup_dir&amp;rdquo; parameter when handling the &amp;ldquo;Backups&amp;rdquo; action within the &amp;ldquo;Administration&amp;rdquo; module is not properly sanitized before being used in a file operation. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple PHP Code Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-07/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   When handling the &amp;ldquo;Locale&amp;rdquo; action within the &amp;ldquo;Administration&amp;rdquo; module the application allows to inject arbitrary settings into the config_override.php file. This can be exploited by malicious users to inject and execute arbitrary PHP code by e.g. setting to .php the file extension for the system log file. Successful exploitation of this vulnerability requires a System Administrator account.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple PHP Object Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-08/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   The vulnerability exists because the &amp;quot;/modules/Emails/DetailView.php&amp;quot; script is using the unserialize() PHP function with the &amp;ldquo;campaign_data&amp;rdquo; field of the table, and such a value can be arbitrarily manipulated through the &amp;ldquo;save2&amp;rdquo; action. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple Reflected Cross-Site Scripting Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-03/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   User input passed through the &amp;ldquo;form&amp;rdquo; parameter when handling the &amp;ldquo;Popup&amp;rdquo; action within the &amp;ldquo;DataSets&amp;rdquo; module is not properly sanitized before being used to generate HTML output. This can be exploited by malicious users to carry out Reflected Cross-Site Scripting (XSS) attacks.
  User input passed through the &amp;ldquo;name&amp;rdquo; parameter when handling the &amp;ldquo;Popup&amp;rdquo; action within the &amp;ldquo;DataSets&amp;rdquo; module is not properly sanitized before being used to generate HTML output.</description>
    </item>
    
    <item>
      <title>SugarCRM &lt;= 9.0.1 Multiple SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-04/</guid>
      <description>• Software Link: https://www.sugarcrm.com
• Affected Versions: Version 9.0.1 and prior versions, 8.0.3 and prior versions.
• Vulnerabilities Description:   User input passed to the &amp;quot;/pmse_Inbox/changeCaseUser&amp;quot; REST API endpoint is not properly sanitized before being used to construct a SQL query. This can be exploited by malicious users to e.g. read sensitive data from the database through in-band SQL Injection attacks.
  User input passed to the &amp;quot;/pmse_Project/CrmData/activities&amp;quot; REST API endpoint is not properly sanitized before being used to construct a SQL query.</description>
    </item>
    
    <item>
      <title>SuiteCRM &lt;= 7.11.10 Multiple SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2020-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-05/</guid>
      <description>• Software Link: https://suitecrm.com
• Affected Versions: Version 7.11.10 and prior versions.
• Vulnerabilities Description:   The vulnerability is located within the SOAP API, specifically into the set_entries() SOAP function. User input passed through the &amp;ldquo;name_value_lists&amp;rdquo; parameter (specifically the &amp;ldquo;first_name&amp;rdquo; and &amp;ldquo;last_name&amp;rdquo; elements) isn’t properly sanitized before being used to construct a SQL query from within the check_for_duplicate_contacts() function. This can be exploited by malicious users to e.g. read sensitive data from the database through in-bound SQL injection attacks.</description>
    </item>
    
    <item>
      <title>SuiteCRM &lt;= 7.11.11 (action_saveHTMLField) Bean Manipulation Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2020-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-03/</guid>
      <description>• Software Link: https://suitecrm.com
• Affected Versions: Version 7.11.11 and prior versions.
• Vulnerability Description: The vulnerability exists because the HomeController::action_saveHTMLField() method allows to create new beans or modify arbitrary beans’ fields. This can result in second-order SQL Injections or PHP Object Injection attacks.
• Solution: Update to version 7.11.12, 7.10.24, or later.
• Disclosure Timeline: [19/09/2019] – Vendor notified
[20/09/2019] – Vendor acknowledgement
[12/11/2019] – Vendor contacted again asking for updates, no response</description>
    </item>
    
    <item>
      <title>SuiteCRM &lt;= 7.11.11 (add_to_prospect_list) Broken Access Control Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2020-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-04/</guid>
      <description>• Software Link: https://suitecrm.com
• Affected Versions: Version 7.11.11 and prior versions.
• Vulnerability Description: There is a Local File Inclusion vulnerability within the add_to_prospect_list() function. User input passed through the &amp;ldquo;parent_module&amp;rdquo; and &amp;ldquo;parent_type&amp;rdquo; parameters is not properly validated before being used in a call to the include() PHP function. This can be exploited to include arbitrary .php files within the webroot and potentially bypass authorization mechanisms (for instance, by setting the &amp;ldquo;parent_module&amp;rdquo; parameter to &amp;ldquo;Administration&amp;rdquo; and the &amp;ldquo;parent_type&amp;rdquo; parameter to &amp;ldquo;expandDatabase&amp;rdquo; or any other administrative action which does not implement ACL checks).</description>
    </item>
    
    <item>
      <title>SuiteCRM &lt;= 7.11.11 Multiple Phar Deserialization Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2020-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-02/</guid>
      <description>• Software Link: https://suitecrm.com
• Affected Versions: Version 7.11.11 and prior versions.
• Vulnerabilities Description:   User input passed through the &amp;ldquo;backup_dir&amp;rdquo; parameter when handling the &amp;ldquo;Backups&amp;rdquo; action within the &amp;ldquo;Administration&amp;rdquo; module is not properly sanitized before being used in a file operation. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.</description>
    </item>
    
    <item>
      <title>SuiteCRM &lt;= 7.11.11 Second-Order PHP Object Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2020-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2020-01/</guid>
      <description>• Software Link: https://suitecrm.com
• Affected Versions: Version 7.11.11 and prior versions.
• Vulnerabilities Description:   The vulnerability exists because the EmailsControllerActionGetFromFields::getEmailSignatures() method is using the unserialize() PHP function with the account_signatures user preference, and such a value can be arbitrarily manipulated by evil users through the EmailUIAjax interface. This can be exploited to inject arbitrary PHP objects into the application scope, allowing an attacker to perform a variety of attacks, such as executing arbitrary PHP code.</description>
    </item>
    
    <item>
      <title>Support Incident Tracker &lt;= 3.65 (translate.php) Path Disclosure Weakness</title>
      <link>https://karmainsecurity.com/vuln-67/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-67/</guid>
      <description>Description: Support Incident Tracker contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a direct request to translate.php, which discloses the software&amp;rsquo;s installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
References:  CVE-2011-5075 EDB-18132  Disclosure Date: November 19, 2011</description>
    </item>
    
    <item>
      <title>Support Incident Tracker &lt;= 3.65 PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-68/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-68/</guid>
      <description>Description: Support Incident Tracker contains a flaw that allows authenticated users to inject and execute arbitrary PHP code. Input passed via keys of the $_POST array to the translate.php script is not properly sanitized before being stored in a file with a .php extension into the &amp;lsquo;i18n&amp;rsquo; directory.
References:  CVE-2011-4337 BID-50742 EDB-18132  Disclosure Date: November 19, 2011</description>
    </item>
    
    <item>
      <title>Symantec Web Gateway &lt;= 5.2.1 (restore.php) OS Command Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-19/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-19/</guid>
      <description>• Software Link: http://www.symantec.com/web-gateway
• Affected Versions: Version 5.2.1 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /spywall/restore.php script:
79$temp_file_name = trim($restore_file[&amp;#34;tmp_name&amp;#34;]); 80$upload_orig_name = basename($restore_file[&amp;#39;name&amp;#39;]); 81//do this in case user change .des3 extnsion to .bak which is idential to backup file,will case unzip not work 82$temp_orig_name = str_replace(&amp;#34;.bak&amp;#34;, &amp;#34;.des3&amp;#34;,$upload_orig_name); 83 84$filePath = &amp;#34;/tmp/$temp_orig_name&amp;#34;; 85 86syscall (&amp;#34;sudo rm -f $filePath&amp;#34;); //make sure this file not exists. 87syscall (&amp;#34;sudo rm -f /tmp/backup_*.</description>
    </item>
    
    <item>
      <title>Symantec Web Gateway &lt;= 5.2.2 (new_whitelist.php) OS Command Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2016-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2016-12/</guid>
      <description>• Software Link: https://www.symantec.com
• Affected Versions: Version 5.1.1.24, 5.2.1.80 and 5.2.2.118.
Other versions might be affected.
• Vulnerability Description: The vulnerable code is located in the /spywall/new_whitelist.php script:
141$isNew = $_POST[&amp;#39;isNew&amp;#39;]; 142$sid = $_POST[&amp;#39;sid&amp;#39;]; 143$exceptions = array(); 144$last_modified = time(); 145/* validate input */ 146 147if (!$sid &amp;amp;&amp;amp; !isValidWhiteDomain($white_ip) &amp;amp;&amp;amp; !isIpSubnet($white_ip)) { 148 $errors[&amp;#39;white_ip&amp;#39;] = &amp;#39;Please enter a valid domain or IP address or IP/mask.&amp;#39;; 149} The vulnerability exists because the validation checks may be bypassed by setting the ‘sid’ POST parameter to a value different from zero.</description>
    </item>
    
    <item>
      <title>TestLink &lt;= 1.9.12 (database.class.php) Path Disclosure Weakness</title>
      <link>https://karmainsecurity.com/KIS-2014-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-12/</guid>
      <description>• Software Link: http://testlink.org
• Affected Versions: Version 1.9.12 and prior versions.
• Weakness Description: The vulnerable code is located in the /lib/functions/database.class.php script:
208if(defined(&amp;#39;DBUG_ON&amp;#39;) &amp;amp;&amp;amp; DBUG_ON == 1) 209{ 210 echo &amp;#34;&amp;lt;pre&amp;gt;&amp;#34;; debug_print_backtrace(); echo &amp;#34;&amp;lt;/pre&amp;gt;&amp;#34;; 211} 212else 213{ 214 echo &amp;#34;&amp;lt;pre&amp;gt;&amp;#34;; debug_print_backtrace(DEBUG_BACKTRACE_IGNORE_ARGS); echo &amp;#34;&amp;lt;/pre&amp;gt;&amp;#34;; 215} The weakness exists due to this script reveals debug information generated by the debug_print_backtrace() PHP function. This can be exploited to gain knowledge of the web root directory by sending direct requests to certain scripts.</description>
    </item>
    
    <item>
      <title>TestLink &lt;= 1.9.12 (execSetResults.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-11/</guid>
      <description>• Software Link: http://testlink.org
• Affected Versions: Version 1.9.12 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /lib/execute/execSetResults.php script:
428if(is_string($args-&amp;gt;filter_status) &amp;amp;&amp;amp; strlen($args-&amp;gt;filter_status) &amp;gt; 1) 429{ 430 $args-&amp;gt;filter_status = unserialize($args-&amp;gt;filter_status); 431} User input passed through the &amp;ldquo;filter_result_result&amp;rdquo; request parameter is not properly sanitized before being used in a call to the unserialize() PHP function at line 430. This can be exploited to inject arbitrary PHP objects into the application scope, and could allow an attacker to delete arbitrary files, carry out Server-Side Request Forgery (SSRF), SQL Injection, or Local/Remote File Inclusion attacks via specially crafted serialized objects.</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 24.0 (grid.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-03/</guid>
      <description>• Software Link: https://tiki.org
• Affected Versions: Version 24.0 and prior versions.
• Vulnerability Description: The vulnerability is located in the /lib/sheet/grid.php script, specifically into the TikiSheetSerializeHandler::_load() method, which is using the unserialize() PHP function with user-controlled input. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code. Successful exploitation of this vulnerability requires the “Spreadsheets” feature to be enabled and an account with permissions to create a new sheet.</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 24.0 (structlib.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-02/</guid>
      <description>• Software Link: https://tiki.org
• Affected Versions: Version 24.0 and prior versions.
• Vulnerability Description: The vulnerability is located in the /lib/structures/structlib.php script, specifically in the StructLib::structure_to_webhelp() method, which is using an eval() call with user-controlled input. This can be exploited by malicious users to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires the &amp;ldquo;feature_create_webhelp&amp;rdquo; to be enabled and an account with permissions to create a wiki page.</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 24.1 (tikiimporter_blog_wordpress.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2023-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-04/</guid>
      <description>• Software Link: https://tiki.org
• Affected Versions: Version 24.1 and prior versions.
• Vulnerability Description: The vulnerability is located in the /lib/importer/tikiimporter_blog_wordpress.php script. Specifically, when importing data from WordPress sites through the Tiki Importer, user input passed through the uploaded XML file is being used in a call to the unserialize() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 25.0 Two Cross-Site Request Forgery Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2023-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2023-01/</guid>
      <description>• Software Link: https://tiki.org
• Affected Versions: Version 25.0 and prior versions.
• Vulnerabilities Description:   The /tiki-importer.php script does not implement any protection against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker might force an authenticated user to import arbitrary content (wiki pages) into TikiWiki by tricking a victim user into browsing to a specially crafted web page.
  The /tiki-import_sheet.php script does not implement any protection against Cross-Site Request Forgery (CSRF) attacks.</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 28.3 Two Server-Side Template Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2025-03/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-03/</guid>
      <description>• Software Link: https://tiki.org
• Affected Versions: Version 28.3 and prior 28.x versions.
Version 27.2 and prior 27.x versions.
Version 24.8 and prior 24.x versions.
Version 21.12 and prior 21.x versions.
• Vulnerabilities Description: Tiki Wiki CMS Groupware is affected by two Server-Side Template Injection (SSTI) vulnerabilities, which can be exploited by creating specially crafted wiki pages.
The first vulnerability can be exploited by abusing the customsearch plugin to, e.g., write arbitrary PHP files on the web server by using the following as the source code for a wiki page:</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 8.2 PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-76/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-76/</guid>
      <description>Description: Tiki Wiki CMS Groupware contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack which can lead to arbitrary PHP code execution. The flaw exists within the lib/wiki-plugins/wikiplugin_snarf.php script, which not properly sanitize input passed via the &amp;lsquo;regex&amp;rsquo; and &amp;lsquo;regexres&amp;rsquo; parameters to the snarf_ajax.php script before using it in a preg_replace() call.
References:  CVE-2011-4558 BID-51168 EDB-18265 http://info.tiki.org/article185-Tiki-Security-Patches-Available-for-8-3-and-6-6-LTS  Disclosure Date: December 22, 2011</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 8.3 Multiple Path Disclosure Weaknesses</title>
      <link>https://karmainsecurity.com/vuln-84/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-84/</guid>
      <description>Description: TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
References:  CVE-2012-3996 EDB-19573 http://info.tiki.org/article191-Tiki-Releases-8-4  Disclosure Date: July 4, 2012</description>
    </item>
    
    <item>
      <title>Tiki Wiki CMS Groupware &lt;= 9.2 Multiple PHP Object Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/vuln-85/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-85/</guid>
      <description>Description: Tiki Wiki CMS Groupware contains a flaw that is triggered when certain scripts fail to properly sanitize user-supplied input before being used in an unserialize() call. With a specially crafted serialized object an attacker might be able to create a file containing arbitrary PHP code abusing the __destruct() method of a Zend Framework class.
References:  CVE-2012-0911 BID-54298 EDB-19573 http://info.tiki.org/article210-Tiki-10-0-is-here  Disclosure Date: July 4, 2012</description>
    </item>
    
    <item>
      <title>TinyWebGallery &lt;= 1.7.6 (init.php) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-41/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-41/</guid>
      <description>Description: TinyWebGallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /admin/_include/init.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied to the lang parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands which will be executed by the vulnerable script. In addition, this flaw can potentially be used to disclose the contents of any file on the system.</description>
    </item>
    
    <item>
      <title>Traq &lt;= 2.3 Authentication Bypass / PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-75/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-75/</guid>
      <description>Description: Traq contains a flaw that allows a remote attacker to execute arbitrary PHP code. The flaw is caused due to admin rights not properly being restricted in the authenticate() function defined in admincp/common.php. This allows attackers to bypass the authentication mechanism and have access to admin functionalities, resulting in execution of arbitrary PHP code.
References:  BID-50961 EDB-18213  Disclosure Date: December 7, 2011</description>
    </item>
    
    <item>
      <title>Tuleap &lt;= 7.6-4 (register.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-13/</guid>
      <description>• Software Link: https://www.tuleap.org
• Affected Versions: Version 7.6-4 and prior versions.
• Vulnerability Description: The vulnerable code is located in the /src/www/project/register.php script:
27$request = HTTPRequest::instance(); 28 29if (Config::get(&amp;#39;sys_create_project_in_one_step&amp;#39;)) { 30 $router = new Project_OneStepCreation_OneStepCreationRouter( 31 ProjectManager::instance(), 32 new Project_CustomDescription_CustomDescriptionFactory(new Project_CustomDescription_CustomDescriptionDao()) 33 ); 34 $router-&amp;gt;route($request); 35 exit; 36} 37 38$current_step = $request-&amp;gt;exist(&amp;#39;current_step&amp;#39;) ? $request-&amp;gt;get(&amp;#39;current_step&amp;#39;) : 0; 39$data = $request-&amp;gt;exist(&amp;#39;data&amp;#39;) ? unserialize($request-&amp;gt;get(&amp;#39;data&amp;#39;)) : array(); User input passed through the &amp;ldquo;data&amp;rdquo; request parameter is not properly sanitized before being used in a call to the unserialize() PHP function at line 39.</description>
    </item>
    
    <item>
      <title>Tuleap &lt;= 9.6 Second-Order PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2017-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2017-02/</guid>
      <description>• Software Link: https://www.tuleap.org
• Affected Versions: All versions from 5.0 to 9.6.
• Vulnerability Description: The vulnerable code can be triggered through the User::getRecentElements() method defined in /src/common/user/User.class.php:
1425public function getRecentElements() { 1426 if ($recent_elements = $this-&amp;gt;getPreference(self::PREFERENCE_RECENT_ELEMENTS)) { 1427 if ($recent_elements = unserialize($recent_elements)) { 1428 if (is_array($recent_elements)) { 1429 return $recent_elements; 1430 } 1431 } 1432 //somthing wrong happen. Delete the preference 1433 $this-&amp;gt;delPreference(self::PREFERENCE_RECENT_ELEMENTS); 1434 } 1435 return array(); 1436} The vulnerability exists because this method is using the unserialize() PHP function with a value that can be arbitrarily manipulated by a user through the REST API interface.</description>
    </item>
    
    <item>
      <title>UNA CMS &lt;= 14.0.0-RC4 (BxBaseMenuSetAclLevel.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2025-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2025-01/</guid>
      <description>• Software Links: https://unacms.com
https://github.com/unacms/una
• Affected Versions: All versions from 9.0.0-RC1 to 14.0.0-RC4.
• Vulnerability Description: The vulnerability is located in the /template/scripts/BxBaseMenuSetAclLevel.php script.
Specifically, within the BxBaseMenuSetAclLevel::getCode() method:
45 public function getCode ($mixedProfileId = 0) 46 { 47 $this-&amp;gt;mixedProfileId = $mixedProfileId; 48 49 if (isset($_SERVER[&amp;#39;HTTP_X_REQUESTED_WITH&amp;#39;]) &amp;amp;&amp;amp; $_SERVER[&amp;#39;HTTP_X_REQUESTED_WITH&amp;#39;] == &amp;#39;XMLHttpRequest&amp;#39; &amp;amp;&amp;amp; ($mixedProfileId = bx_get(&amp;#39;profile_id&amp;#39;, &amp;#39;post&amp;#39;)) &amp;amp;&amp;amp; ($iAclLevelId = bx_get(&amp;#39;level_id&amp;#39;, &amp;#39;post&amp;#39;))) { 50 $mixedProfileId = urldecode($mixedProfileId); 51 if(!is_numeric($mixedProfileId)) 52 $mixedProfileId = unserialize($mixedProfileId); 53 54 echoJson($this-&amp;gt;setMembership($mixedProfileId, $iAclLevelId, bx_get(&amp;#39;duration&amp;#39;, &amp;#39;post&amp;#39;) !</description>
    </item>
    
    <item>
      <title>Vanilla Forums &lt;= 2.0.18.5 (class.utilitycontroller.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-09/</guid>
      <description>• Software Link: http://vanillaforums.org
• Affected Versions: All versions from 2.0 to 2.0.18.5.
• Vulnerability Description: The vulnerable code is located in /applications/dashboard/controllers/class.utilitycontroller.php:
316// Get the message, response, and transientkey 317$Messages = TrueStripSlashes(GetValue(&amp;#39;Messages&amp;#39;, $_POST)); 318$Response = TrueStripSlashes(GetValue(&amp;#39;Response&amp;#39;, $_POST)); 319$TransientKey = GetIncomingValue(&amp;#39;TransientKey&amp;#39;, &amp;#39;&amp;#39;); 320 321// If the key validates 322$Session = Gdn::Session(); 323if ($Session-&amp;gt;ValidateTransientKey($TransientKey)) { 324 // If messages wasn&amp;#39;t empty 325 if ($Messages != &amp;#39;&amp;#39;) { 326 // Unserialize them &amp;amp; save them if necessary 327 $Messages = Gdn_Format::Unserialize($Messages); 358// If the response wasn&amp;#39;t empty, save it in the config 359if ($Response !</description>
    </item>
    
    <item>
      <title>vBulletin &lt;= 5.5.4 (updateAvatar) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2019-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-02/</guid>
      <description>• Software Link: https://www.vbulletin.com
• Affected Versions: Version 5.5.4 and prior versions.
• Vulnerability Description: User input passed through the &amp;ldquo;data[extension]&amp;quot; and &amp;ldquo;data[filedata]&amp;quot; parameters to the &amp;ldquo;ajax/api/user/updateAvatar&amp;rdquo; endpoint is not properly validated before being used to update users’ avatars. This can be exploited to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires the “Save Avatars as Files” option to be enabled (disabled by default).
• Proof of Concept: https://www.</description>
    </item>
    
    <item>
      <title>vBulletin &lt;= 5.5.4 Two SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2019-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-01/</guid>
      <description>• Software Link: https://www.vbulletin.com/
• Affected Versions: Version 5.5.4 and prior versions.
• Vulnerabilities Description:   User input passed through keys of the &amp;ldquo;where&amp;rdquo; parameter to the &amp;ldquo;ajax/api/hook/getHookList&amp;rdquo; endpoint is not properly validated before being used in an SQL query. This can be exploited to e.g. read sensitive data from the database through in-band SQL injection attacks. Successful exploitation of this vulnerability requires an user account with the &amp;ldquo;canadminproducts&amp;rdquo; or &amp;ldquo;canadminstyles&amp;rdquo; permission.</description>
    </item>
    
    <item>
      <title>vtiger CRM &lt;= 5.4.0 (customerportal.php) Two Local File Inclusion Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2013-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-05/</guid>
      <description>• Software Link: http://www.vtiger.com
• Affected Versions: All versions from 5.1.0 to 5.4.0.
All versions from 5.2.0 to 5.4.0.
• Vulnerabilities Description:  The vulnerable code is located in the get_list_values() SOAP method defined in /soap/customerportal.php:  1528function get_list_values($id,$module,$sessionid,$only_mine=&amp;#39;true&amp;#39;) 1529{ 1530 require_once(&amp;#39;modules/&amp;#39;.$module.&amp;#39;/&amp;#39;.$module.&amp;#39;.php&amp;#39;); 1531 require_once(&amp;#39;include/utils/UserInfoUtil.php&amp;#39;); 1532 global $adb,$log,$current_user; 1533 $log-&amp;gt;debug(&amp;#34;Entering customer portal function get_list_values&amp;#34;); The vulnerable code is located in the get_project_components() SOAP method defined in /soap/customerportal.php:  2778function get_project_components($id,$module,$customerid,$sessionid) { 2779 require_once(&amp;#34;modules/$module/$module.</description>
    </item>
    
    <item>
      <title>vtiger CRM &lt;= 5.4.0 (SOAP Services) Authentication Bypass Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-08/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-08/</guid>
      <description>• Software Link: http://www.vtiger.com
• Affected Versions: All versions from 5.1.0 to 5.4.0.
• Vulnerability Description: The vulnerable code is located in the validateSession() function, which is defined in multiple SOAP services:
function validateSession($username, $sessionid) { global $adb,$current_user; $adb-&amp;gt;println(&amp;#34;Inside function validateSession($username, $sessionid)&amp;#34;); require_once(&amp;#34;modules/Users/Users.php&amp;#34;); $seed_user = new Users(); $id = $seed_user-&amp;gt;retrieve_user_id($username); $server_sessionid = getServerSessionId($id); $adb-&amp;gt;println(&amp;#34;Checking Server session id and customer input session id ==&amp;gt; $server_sessionid== $sessionid&amp;#34;); if($server_sessionid == $sessionid) { $adb-&amp;gt;println(&amp;#34;Session id match.</description>
    </item>
    
    <item>
      <title>vtiger CRM &lt;= 5.4.0 (SOAP Services) Multiple SQL Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2013-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-06/</guid>
      <description>• Software Link: http://www.vtiger.com
• Affected Versions: All versions from 5.0.0 to 5.4.0.
• Vulnerabilities Description:  The vulnerable code is located in the get_picklists() SOAP method defined in /soap/customerportal.php:  1177$id = $input_array[&amp;#39;id&amp;#39;]; 1178$sessionid = $input_array[&amp;#39;sessionid&amp;#39;]; 1179$picklist_name = $adb-&amp;gt;sql_escape_string($input_array[&amp;#39;picklist_name&amp;#39;]); 1180 1181if(!validateSession($id,$sessionid)) 1182return null; 1183 1184$picklist_array = Array(); 1185 1186$admin_role = &amp;#39;H2&amp;#39;; 1187$userid = getPortalUserid(); 1188$roleres = $adb-&amp;gt;pquery(&amp;#34;SELECT roleid from vtiger_user2role where userid = ?&amp;#34;, array($userid)); 1189$RowCount = $adb-&amp;gt;num_rows($roleres); 1190if($RowCount &amp;gt; 0){ 1191 $admin_role = $adb-&amp;gt;query_result($roleres,0,&amp;#39;roleid&amp;#39;); 1192} 1193 1194$res = $adb-&amp;gt;pquery(&amp;#34;select vtiger_&amp;#34;.</description>
    </item>
    
    <item>
      <title>vtiger CRM &lt;= 5.4.0 (vtigerolservice.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2013-07/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2013-07/</guid>
      <description>• Software Link: http://www.vtiger.com
• Affected Versions: All versions from 5.0.0 to 5.4.0.
• Vulnerability Description: The vulnerable code is located in the AddEmailAttachment() SOAP method defined in /soap/vtigerolservice.php:
458function AddEmailAttachment($emailid,$filedata,$filename,$filesize,$filetype,$username,$session) 459{ 460 if(!validateSession($username,$session)) 461 return null; 462 global $adb; 463 require_once(&amp;#39;modules/Users/Users.php&amp;#39;); 464 require_once(&amp;#39;include/utils/utils.php&amp;#39;); 465 $filename = preg_replace(&amp;#39;/\s+/&amp;#39;, &amp;#39;_&amp;#39;, $filename);//replace space with _ in filename 466 $date_var = date(&amp;#39;Y-m-d H:i:s&amp;#39;); 467 468 $seed_user = new Users(); 469 $user_id = $seed_user-&amp;gt;retrieve_user_id($username); 470 471 $crmid = $adb-&amp;gt;getUniqueID(&amp;#34;vtiger_crmentity&amp;#34;); 472 473 $upload_file_path = decideFilePath(); 474 475 $handle = fopen($upload_file_path.</description>
    </item>
    
    <item>
      <title>WebCalendar &lt;= 1.2.4 (install/index.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-81/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-81/</guid>
      <description>Description: WebCalendar contains an access restriction weakness when passing input to the install/index.php script. This allows an attacker to update includes/settings.php with arbitrary values, leading to execution of arbitrary PHP code.
References:  CVE-2012-1495 CVE-2012-5385 BID-53207 EDB-18775  Disclosure Date: April 23, 2012</description>
    </item>
    
    <item>
      <title>WebCalendar &lt;= 1.2.4 (pref.php) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-80/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-80/</guid>
      <description>Description: WebCalendar contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the pref.php script not properly sanitizing user-supplied input to the &amp;lsquo;pref_THEME&amp;rsquo; parameter. This can be exploited to include arbitrary files from local resources via directory traversal attacks and URL-encoded NULL bytes. In addition, this flaw could be used to disclose the contents of any file on the system accessible by the web server.</description>
    </item>
    
    <item>
      <title>WeBid &lt;= 1.0.2 (feedback.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-48/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-48/</guid>
      <description>Description: WeBid contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the feedback.php script not properly sanitizing user-supplied input to the &amp;lsquo;auction_id&amp;rsquo; parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  BID-48555 EDB-17487 http://www.webidsupport.com/forums/showthread.php?3892  Disclosure Date: July 4, 2011</description>
    </item>
    
    <item>
      <title>WeBid &lt;= 1.0.2 (includes/converter.inc.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-45/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-45/</guid>
      <description>Description: WeBid contains a flaw which allows a remote attacker to inject and execute arbitrary PHP code. The issue is due to user-supplied input passed via the &amp;lsquo;from&amp;rsquo; and &amp;lsquo;to&amp;rsquo; POST parameters to converter.php is not properly sanitized before being stored in includes/currencies.php.
References:  BID-48554 EDB-17487 http://www.webidsupport.com/forums/showthread.php?3892  Disclosure Date: July 4, 2011</description>
    </item>
    
    <item>
      <title>WeBid &lt;= 1.0.2 (includes/messages.inc.php) Local File Inclusion Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-44/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-44/</guid>
      <description>Description: WeBid contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to user input passed to the index.php script not being properly sanitized in the includes/messages.inc.php script, specifically directory traversal style attacks (e.g., ../../) supplied to the &amp;lsquo;lan&amp;rsquo; parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script.</description>
    </item>
    
    <item>
      <title>WeBid &lt;= 1.0.2 (logout.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-47/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-47/</guid>
      <description>Description: WeBid contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the logout.php script not properly sanitizing user-supplied input to the &amp;lsquo;WEBID_RM_ID&amp;rsquo; cookie. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  BID-48555 EDB-17487 http://www.webidsupport.com/forums/showthread.php?3892  Disclosure Date: July 4, 2011</description>
    </item>
    
    <item>
      <title>WeBid &lt;= 1.0.2 (user_login.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-46/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-46/</guid>
      <description>Description: WeBid contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the user_login.php script not properly sanitize user-supplied input passed via the &amp;lsquo;WEBID_ONLINE&amp;rsquo; cookie. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  BID-48555 EDB-17487 http://www.webidsupport.com/forums/showthread.php?3892  Disclosure Date: July 4, 2011</description>
    </item>
    
    <item>
      <title>WikkaWiki &lt;= 1.3.2 (files.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-73/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-73/</guid>
      <description>Description: WikkaWiki contains a flaw that allows a remote user to execute arbitrary PHP code due to the actions/files/files.php script not properly verify user-uploaded files. When INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file with multiple extensions.
References:  CVE-2011-4449 BID-50866 EDB-18177 http://blog.</description>
    </item>
    
    <item>
      <title>WikkaWiki &lt;= 1.3.2 (files.xml.php) Path Traversal Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-72/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-72/</guid>
      <description>Description: WikkaWiki contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the /handlers/files.xml/files.xml.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack may allow an attacker to access and delete arbitrary files.
References:  CVE-2011-4450 BID-50866 EDB-18177 http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/  Disclosure Date: November 30, 2011</description>
    </item>
    
    <item>
      <title>WikkaWiki &lt;= 1.3.2 (libs/Wakka.class.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-71/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-71/</guid>
      <description>Description: WikkaWiki contains a flaw that allows a remote user to execute arbitrary PHP code. The flaw is due to the libs/Wakka.class.php script. When the &amp;lsquo;spam_logging&amp;rsquo; option is enabled, a remote attackers might be able to write arbitrary PHP code to the &amp;lsquo;spamlog_path&amp;rsquo; file via the User-Agent HTTP header in an addcomment request.
References:  CVE-2011-4451 BID-50866 EDB-18177 http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/  Disclosure Date: November 30, 2011</description>
    </item>
    
    <item>
      <title>WikkaWiki &lt;= 1.3.2 (usersettings.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-74/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-74/</guid>
      <description>Description: WikkaWiki contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /actions/usersettings/usersettings.php script not properly sanitizing user input passed through the &#39;default_comment_display&#39; parameter during an update actions. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
References:  CVE-2011-4448 BID-50866 EDB-18177 http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/  Disclosure Date: November 30, 2011</description>
    </item>
    
    <item>
      <title>WikkaWiki &lt;= 1.3.2 Cross-Site Request Forgery Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-70/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-70/</guid>
      <description>Description: WikkaWiki contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for admin functions, such as deleting user accounts. By using a crafted URL (e.g., a crafted GET request inside an &amp;quot;img&amp;quot; tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application.</description>
    </item>
    
    <item>
      <title>WordPress Kish Guest Posting &lt;= 1.2 Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-78/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-78/</guid>
      <description>Description: The Kish Guest Posting Plugin for WordPress contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the plugin uses the uploadify.php script, which does not properly verify or sanitize user-uploaded files.
References:  CVE-2012-5318 CVE-2012-1125 BID-51638 EDB-18412  Disclosure Date: January 23, 2012</description>
    </item>
    
    <item>
      <title>Wordpress Zingiri Web Shop &lt;= 2.2.3 PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-65/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-65/</guid>
      <description>Description: Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin used in the Zingiri Web Shop plugin for WordPress allows remote attackers to inject arbitrary PHP code into data.php via the selected document, as demonstrated by a call to ajax_file_cut.php and then to ajax_save_name.php.
References:  BID-50700 EDB-18111  Disclosure Date: November 13, 2011</description>
    </item>
    
    <item>
      <title>X2Engine &lt;= 3.7.5 (ProfileController.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-04/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-04/</guid>
      <description>• Software Link: http://www.x2engine.com
• Affected Versions: Version 3.7.5 and probably prior versions.
• Vulnerability Description: The vulnerability exists in the /protected/controllers/ProfileController.php script, specifically in the actionUploadPhoto() method, allowing to upload arbitrary files. This can be exploited to execute arbitrary PHP code by uploading a malicious PHP script.
• Solution: Apply the vendor patch or upgrade to version 4.0.
• Disclosure Timeline: [20/03/2014] – Vendor notified
[20/03/2014] – Vendor releases updates</description>
    </item>
    
    <item>
      <title>X2Engine &lt;= 4.1.7 (FileUploadsFilter.php) Unrestricted File Upload Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-10/</guid>
      <description>• Software Link: http://www.x2engine.com
• Affected Versions: Version 4.1.7 and probably prior versions.
• Vulnerability Description: The vulnerability exists because of the FileUploadsFilter::EXT_BLACKLIST constant, which is a regular expression for blacklisted files. Due to a lack of case-insensitive matching, the global upload filter could be bypassed by uploading a malicious file with capital letters within the extension. This can be exploited to upload and execute arbitrary PHP scripts if X2Engine is running on a case-insensitive filesystem or if the web server is configured to handle files’ extensions in a case-insensitive fashion.</description>
    </item>
    
    <item>
      <title>X2Engine &lt;= 4.1.7 (SiteController.php) PHP Object Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2014-09/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-09/</guid>
      <description>• Software Link: http://www.x2engine.com
• Affected Versions: All versions from 2.8 to 4.1.7.
• Vulnerability Description: The vulnerable code is located in the actionSendErrorReport() method defined in /protected/controllers/SiteController.php:
153public function actionSendErrorReport(){ 154 if(isset($_POST[&amp;#39;report&amp;#39;])){ 155 $errorReport = $_POST[&amp;#39;report&amp;#39;]; 156 $errorReport = unserialize(base64_decode($errorReport)); 157 if(isset($_POST[&amp;#39;email&amp;#39;])){ 158 $errorReport[&amp;#39;email&amp;#39;] = $_POST[&amp;#39;email&amp;#39;]; 159 } User input passed through the &amp;ldquo;report&amp;rdquo; POST parameter is not properly sanitized before being used in a call to the unserialize() PHP function at line 156.</description>
    </item>
    
    <item>
      <title>XenForo &lt;= 2.2.13 (ArchiveImport.php) Zip Slip Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2024-01/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-01/</guid>
      <description>• Software Link: https://xenforo.com
• Affected Versions: Version 2.2.13 and prior versions.
• Vulnerability Description: The vulnerability is located in the /src/XF/Service/Style/ArchiveImport.php script.
Specifically, into the ArchiveImport::extractFilesToTempDir() method:
198	public function extractFilesToTempDir() 199	{ 200	$zip = $this-&amp;gt;zip(); 201	$DS = \XF::$DS; 202 203	if ($this-&amp;gt;extracted) 204	{ 205	return; 206	} 207 208	for ($i = 0; $i &amp;lt; $zip-&amp;gt;numFiles; $i++) 209	{ 210	$zipFileName = $zip-&amp;gt;getNameIndex($i); 211	$fsFileName = $this-&amp;gt;getFsFileNameFromZipName($zipFileName); 212	if ($fsFileName === null) 213	{ 214	continue; 215	} 216 217	$finalFileName = $this-&amp;gt;tempDir .</description>
    </item>
    
    <item>
      <title>XenForo &lt;= 2.2.15 (Template System) Remote Code Execution Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2024-06/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-06/</guid>
      <description>• Software Link: https://xenforo.com
• Affected Versions: Version 2.2.15 and prior versions.
• Vulnerability Description: XenForo implements a template system which gives complete control over the layout of XenForo pages. Through these templates, it might be possible to call certain &amp;ldquo;callback methods&amp;rdquo;, however there is a sort of &amp;ldquo;sandbox&amp;rdquo; which allows to solely call read-only methods: a method is to be considered read-only when it begins with one of the allowed prefixes, such as &amp;ldquo;get&amp;rdquo; or &amp;ldquo;filter&amp;rdquo;.</description>
    </item>
    
    <item>
      <title>XenForo &lt;= 2.2.15 (Widget::actionSave) Cross-Site Request Forgery Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2024-05/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2024-05/</guid>
      <description>• Software Link: https://xenforo.com
• Affected Versions: Version 2.2.15 and prior versions.
• Vulnerability Description: The XF\Admin\Controller\Widget::actionSave() method, defined into the /src/XF/Admin/Controller/Widget.php script, does not check whether the current HTTP request is a POST or a GET before saving a widget. XenForo does perform anti-CSRF checks for POST requests only, as such this method can be abused in a Cross-Site Request Forgery (CSRF) attack to create/modify arbitrary XenForo widgets via GET requests, and this can also be exploited in tandem with KIS-2024-06 to perform CSRF-based Remote Code Execution (RCE) attacks.</description>
    </item>
    
    <item>
      <title>YouPHPTube &lt;= 7.7 (getChat.json.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/KIS-2019-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2019-10/</guid>
      <description>• Software Link: https://www.youphptube.com
• Affected Versions: Version 7.7 and prior versions.
• Vulnerability Description: User input passed through the &amp;ldquo;live_stream_code&amp;rdquo; POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized before being used to construct a SQL query. This can be exploited by malicious users to e.g. read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the “Live Chat” plugin to be enabled (disabled by default).</description>
    </item>
    
    <item>
      <title>Zenphoto &lt;= 1.4.1.4 (ajax_create_folder.php) PHP Code Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-64/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-64/</guid>
      <description>Description: Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References:  CVE-2011-4825 BID-50523 EDB-18083 http://www.zenphoto.org/trac/ticket/2005  Disclosure Date: November 5, 2011</description>
    </item>
    
    <item>
      <title>ZeusCMS &lt;= 0.3 (image_viewer.php) Information Disclosure Weakness</title>
      <link>https://karmainsecurity.com/vuln-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-6/</guid>
      <description>Description: Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the dir parameter.
References:  CVE-2007-6623 BID-27058 EDB-4798  Disclosure Date: December 27, 2007</description>
    </item>
    
    <item>
      <title>ZeusCMS &lt;= 0.3 (security.php) SQL Injection Vulnerability</title>
      <link>https://karmainsecurity.com/vuln-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/vuln-7/</guid>
      <description>Description: SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
References:  CVE-2007-6622 BID-27058 EDB-4798  Disclosure Date: December 27, 2007</description>
    </item>
    
    <item>
      <title>Zikula Application Framework &lt;= 1.3.6 Multiple PHP Object Injection Vulnerabilities</title>
      <link>https://karmainsecurity.com/KIS-2014-02/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://karmainsecurity.com/KIS-2014-02/</guid>
      <description>• Software Link: http://zikula.org
• Affected Versions: Version 1.3.6 and probably prior versions.
• Vulnerabilities Description:   Input passed via the &amp;ldquo;authentication_method_ser&amp;rdquo; and &amp;ldquo;authentication_info_ser&amp;rdquo; POST parameters to index.php (when &amp;ldquo;module&amp;rdquo; is set to &amp;ldquo;users&amp;rdquo;, &amp;ldquo;func&amp;rdquo; is set to &amp;ldquo;register&amp;rdquo;, &amp;ldquo;csrftoken&amp;rdquo; is set to a valid value, and &amp;ldquo;registration_info&amp;rdquo; is set to an arbitrary value) is not properly sanitised before being used in a call to the unserialize() PHP function. This can be exploited to e.</description>
    </item>
    
  </channel>
</rss>
