The HTTP media server on DJI drones does not sufficiently limit incoming connections or request rates. An attacker on the internal network can exhaust the connection pool and prevent the DJI Fly application from retrieving media in QuickTransfer mode.
DJI drones expose an unauthenticated DUML command interface over Bluetooth. A nearby attacker can modify wireless settings, obtain access to the internal Wi-Fi network, disrupt Wi-Fi and Bluetooth connections, and potentially reach the flight-control interface.
The HTTP media server on DJI drones serves stored photos and videos without authenticating clients. An attacker on the drone's internal network can enumerate predictable filenames and exfiltrate media that may reveal sensitive locations, people, and operator routines.
DJI drones expose an FTP service with shared hardcoded credentials and no storage quotas in /blackbox/upgrade/. An attacker with internal-network or USB RNDIS access can exhaust storage, overwrite files, prevent flight records and telemetry from being written, and interfere with firmware updates.
DJI drones transmit DUML messages over Bluetooth Low Energy without encryption, exposing Wi-Fi credentials and a trusted-client identifier to a nearby passive attacker. The recovered credentials can be used to join the drone's internal network and interact with exposed services.
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.
A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component.
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component.
A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component.
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a rem
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.