βΌ CVE-2022-28002 βΌ
π Read
via "National Vulnerability Database".
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28001 βΌ
π Read
via "National Vulnerability Database".
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27062 βΌ
π Read
via "National Vulnerability Database".
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27346 βΌ
π Read
via "National Vulnerability Database".
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27348 βΌ
π Read
via "National Vulnerability Database".
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28000 βΌ
π Read
via "National Vulnerability Database".
Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27063 βΌ
π Read
via "National Vulnerability Database".
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27992 βΌ
π Read
via "National Vulnerability Database".
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27064 βΌ
π Read
via "National Vulnerability Database".
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
ποΈ Command injection bug patched in Ruby library for converting AsciiDoc files ποΈ
π Read
via "The Daily Swig".
Ruby server RCE bug gets quashedπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Command injection bug patched in Ruby library for converting AsciiDoc files
Ruby server RCE bug gets quashed
π Friday Five 4/8 π
π Read
via "".
The takedown of a darknet powerhouse, cybercriminals getting more creative, how the most common insider cyber threats may not be quite what you suspect, and more β catch up on this weekβs news with the Friday Five!π Read
via "".
Digital Guardian
Friday Five 4/8
The takedown of a darknet powerhouse, cybercriminals getting more creative, how the most common insider cyber threats may not be quite what you suspect, and more β catch up on this weekβs news with the Friday Five!
βΌ CVE-2021-46437 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46436 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.π Read
via "National Vulnerability Database".
π΄ Security Nihilism Is Putting Your Company β and Its Employees β at Risk π΄
π Read
via "Dark Reading".
Some enterprise security tactics can backfire, pitting IT and security teams against the employees theyβre trying to protect.π Read
via "Dark Reading".
Dark Reading
Security Nihilism Is Putting Your Company β and Its Employees β at Risk
Some enterprise security tactics can backfire, pitting IT and security teams against the employees theyβre trying to protect.
βΌ CVE-2021-46367 βΌ
π Read
via "National Vulnerability Database".
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24229 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.π Read
via "National Vulnerability Database".
ποΈ Third member of FIN7 cybercrime gang jailed over card skimming scheme ποΈ
π Read
via "The Daily Swig".
US authorities sentence pen tester to five years in prisonπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Third member of FIN7 cybercrime gang jailed over card skimming scheme
US authorities sentence pen tester to five years in prison
π΄ ByteChek Founder AJ Yawn Brings Discipline to Everything He Does π΄
π Read
via "Dark Reading".
Security Pro File: The former Army captain, whose security startup is on an upward trajectory, works hard to "make compliance suck less."π Read
via "Dark Reading".
Dark Reading
ByteChek Founder AJ Yawn Brings Discipline to Everything He Does
Security Pro File: The former Army captain, whose security startup is on an upward trajectory, works hard to "make compliance suck less."
β S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast] β
π Read
via "Naked Security".
Latest episode - listen now! Cybersecurity news and advice in plain English.π Read
via "Naked Security".
Naked Security
S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]
Latest episode β listen now! Cybersecurity news and advice in plain English.
β Popular Ruby Asciidoc toolkit patched against critical vuln β get the update now! β
π Read
via "Naked Security".
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.π Read
via "Naked Security".
Naked Security
Popular Ruby Asciidoc toolkit patched against critical vuln β get the update now!
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.
β Google Play Bitten by Sharkbot Info-stealer βAV Solutionβ β
π Read
via "Threat Post".
Google removed six different malicious Android applications targeting mainly users in the U.K. and Italy that were installed about 15,000 times.π Read
via "Threat Post".
Threat Post
Google Play Bitten by Sharkbot Info-stealer βAV Solutionβ
Google removed six different malicious Android applications targeting mainly users in the U.K. and Italy that were installed about 15,000 times.