CVE-2023-1394
published 2023-03-14CVE-2023-1394: A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.74%
50.5th percentile
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222981 was assigned to this vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 3.13.0-193.244 | 3.13.0-193.244 |
| online_graduate_tracer_system_project | online_graduate_tracer_system | — | — |
| sourcecodester | online_graduate_tracer_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv4.7MEDIUM
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux vulnerabilities
osv·2023-09-06·CVSS 4.7
CVE-2023-0458 linux vulnerabilities
linux vulnerabilities
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2023-0458)
It was discovered that a use-after-free vulnerability existed in the IEEE
1394 (Firewire) implementation in the Linux kernel. A privileged attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-3159)
It was discovered that the virtual terminal driver in the Linux kernel
contained a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly expose sensitive
information (kernel memory).
GHSA
GHSA-fjmx-5ghq-2wxh: A vulnerability was found in SourceCodester Online Graduate Tracer System 1
ghsa_unreviewed·2023-03-14
CVE-2023-1394 [CRITICAL] CWE-89 GHSA-fjmx-5ghq-2wxh: A vulnerability was found in SourceCodester Online Graduate Tracer System 1
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222981 was assigned to this vulnerability.
Red Hat
kernel: firewire: net: fix use after free in fwnet_finish_incoming_packet()
vendor_redhat·2025-09-18·CVSS 7.8
CVE-2023-53432 [HIGH] CWE-416 kernel: firewire: net: fix use after free in fwnet_finish_incoming_packet()
kernel: firewire: net: fix use after free in fwnet_finish_incoming_packet()
In the Linux kernel, the following vulnerability has been resolved:
firewire: net: fix use after free in fwnet_finish_incoming_packet()
The netif_rx() function frees the skb so we can't dereference it to
save the skb->len.
Statement: A use-after-free in the FireWire network driver occurred because fwnet_finish_incoming_packet() accessed skb->len after handing the skb to netif_rx(), which may free it. An attacker on the same IEEE-1394 bus can trigger this via normal packet reception, typically resulting in a kernel crash (DoS). Impact is limited to systems with FireWire networking enabled.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Produ
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published