βΌ CVE-2022-28805 βΌ
π Read
via "National Vulnerability Database".
singlevar in lparser.c in Lua through 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28796 βΌ
π Read
via "National Vulnerability Database".
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27061 βΌ
π Read
via "National Vulnerability Database".
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26624 βΌ
π Read
via "National Vulnerability Database".
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27349 βΌ
π Read
via "National Vulnerability Database".
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27991 βΌ
π Read
via "National Vulnerability Database".
Online Banking System in PHP v1 was discovered to contain multiple SQL injection vulnerabilities at /staff_login.php via the Staff ID and Staff Password parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27351 βΌ
π Read
via "National Vulnerability Database".
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28002 βΌ
π Read
via "National Vulnerability Database".
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28001 βΌ
π Read
via "National Vulnerability Database".
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27062 βΌ
π Read
via "National Vulnerability Database".
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27346 βΌ
π Read
via "National Vulnerability Database".
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27348 βΌ
π Read
via "National Vulnerability Database".
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28000 βΌ
π Read
via "National Vulnerability Database".
Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27063 βΌ
π Read
via "National Vulnerability Database".
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27992 βΌ
π Read
via "National Vulnerability Database".
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27064 βΌ
π Read
via "National Vulnerability Database".
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
ποΈ Command injection bug patched in Ruby library for converting AsciiDoc files ποΈ
π Read
via "The Daily Swig".
Ruby server RCE bug gets quashedπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Command injection bug patched in Ruby library for converting AsciiDoc files
Ruby server RCE bug gets quashed
π Friday Five 4/8 π
π Read
via "".
The takedown of a darknet powerhouse, cybercriminals getting more creative, how the most common insider cyber threats may not be quite what you suspect, and more β catch up on this weekβs news with the Friday Five!π Read
via "".
Digital Guardian
Friday Five 4/8
The takedown of a darknet powerhouse, cybercriminals getting more creative, how the most common insider cyber threats may not be quite what you suspect, and more β catch up on this weekβs news with the Friday Five!
βΌ CVE-2021-46437 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46436 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.π Read
via "National Vulnerability Database".
π΄ Security Nihilism Is Putting Your Company β and Its Employees β at Risk π΄
π Read
via "Dark Reading".
Some enterprise security tactics can backfire, pitting IT and security teams against the employees theyβre trying to protect.π Read
via "Dark Reading".
Dark Reading
Security Nihilism Is Putting Your Company β and Its Employees β at Risk
Some enterprise security tactics can backfire, pitting IT and security teams against the employees theyβre trying to protect.