Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2015-10051: Added function to prevent SQL Injection · bony2023/Discussion-Board@26439bc

A vulnerability, which was classified as critical, has been found in bony2023 Discussion-Board. Affected by this issue is the function display_all_replies of the file functions/main.php. The manipulation of the argument str leads to sql injection. The name of the patch is 26439bc4c63632d63ba89ebc0f149b25a9010361. It is recommended to apply a patch to fix this issue. VDB-218378 is the identifier assigned to this vulnerability.

CVE
#sql#vulnerability#web#google#php#perl#ssl

@@ -0,0 +1,61 @@ <style> #ppBody { font-size:11pt; width:100%; margin:0 auto; text-align:justify; }
#ppHeader { font-family:verdana; font-size:21pt; width:100%; margin:0 auto; }
.ppConsistencies { display:none; } </style><div id=’ppHeader’>funchayat.in Privacy Policy</div><div id=’ppBody’><div class=’ppConsistencies’><div class=’col-2’> <div class="quick-links text-center">Information Collection</div> </div><div class=’col-2’> <div class="quick-links text-center">Information Usage</div> </div><div class=’col-2’> <div class="quick-links text-center">Information Protection</div> </div><div class=’col-2’> <div class="quick-links text-center">Cookie Usage</div> </div><div class=’col-2’> <div class="quick-links text-center">3rd Party Disclosure</div> </div><div class=’col-2’> <div class="quick-links text-center">3rd Party Links</div> </div></div><div style=’clear:both;height:10px;’></div><div class=’ppConsistencies’><div class=’col-2’> <div class="col-12 quick-links2 gen-text-center">Google AdSense</div> </div><div class=’col-2’> <div class="col-12 quick-links2 gen-text-center"> Fair Information Practices <div class="col-8 gen-text-left gen-xs-text-center" style="font-size:12px;position:relative;left:20px;">Fair information<br> Practices</div> </div> </div><div class=’col-2’> <div class="col-12 quick-links2 gen-text-center coppa-pad"> COPPA
</div> </div><div class=’col-2’> <div class="col-12 quick-links2 quick4 gen-text-center caloppa-pad"> CalOPPA
</div> </div><div class=’col-2’> <div class="quick-links2 gen-text-center">CAN-SPAM</div> </div><div class=’col-2’> <div class="quick-links2 gen-text-center">Our Contact Information<br></div> </div></div><div style=’clear:both;height:10px;’></div> <div class=’innerText’>This privacy policy has been compiled to better serve those who are concerned with how their ‘Personally identifiable information’ (PII) is being used online. PII, as used in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website.<br></div><span id=’infoCo’></span><br><div class=’grayText’><strong>What personal information do we collect from the people that visit our blog, website or app?</strong></div><br /><div class=’innerText’>When ordering or registering on our site, as appropriate, you may be asked to enter your name, email address, mailing address or other details to help you with your experience.</div><br><div class=’grayText’><strong>When do we collect information?</strong></div><br /><div class=’innerText’>We collect information from you when you register on our site, fill out a form or enter information on our site.</div><br><span id=’infoUs’></span><br><div class=’grayText’><strong>How do we use your information? </strong></div><br /><div class=’innerText’> We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:<br><br></div><div class=’innerText’>      <strong>•</strong> To personalize user’s experience and to allow us to deliver the type of content and product offerings in which you are most interested.</div><div class=’innerText’>      <strong>•</strong> To allow us to better service you in responding to your customer service requests.</div><span id=’infoPro’></span><br><div class=’grayText’><strong>How do we protect visitor information?</strong></div><br /><div class=’innerText’>Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible.<br><br></div><div class=’innerText’>We use regular Malware Scanning.<br><br></div><div class=’innerText’>We do not use an SSL certificate</div><div class=’innerText’>      <strong>•</strong> We only provide articles and information, we never ask for personal or private information like email addresses, or credit card numbers.</div><span id=’coUs’></span><br><div class=’grayText’><strong>Do we use 'cookies’?</strong></div><br /><div class=’innerText’>We do not use cookies for tracking purposes </div><div class=’innerText’><br>You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser (like Internet Explorer) settings. Each browser is a little different, so look at your browser’s Help menu to learn the correct way to modify your cookies.<br></div><br><div class=’innerText’>If you disable cookies off, some features will be disabled that make your site experience more efficient and some of our services will not function properly.</div><br><div class=’innerText’>However, you can still place orders .</div><br><span id=’trDi’></span><br><div class=’grayText’><strong>Third Party Disclosure</strong></div><br /><div class=’innerText’>We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information.</div><span id=’trLi’></span><br><div class=’grayText’><strong>Third party links</strong></div><br /><div class=’innerText’>We do not include or offer third party products or services on our website.</div><span id=’gooAd’></span><br><div class=’blueText’><strong>Google</strong></div><br /><div class=’innerText’>Google’s advertising requirements can be summed up by Google’s Advertising Principles. They are put in place to provide a positive experience for users. https://support.google.com/adwordspolicy/answer/1316548?hl=en <br><br></div><div class=’innerText’>We have not enabled Google AdSense on our site but we may do so in the future.</div><span id=’calOppa’></span><br><div class=’blueText’><strong>California Online Privacy Protection Act</strong></div><br /><div class=’innerText’>CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require a person or company in the United States (and conceivably the world) that operates websites collecting personally identifiable information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals with whom it is being shared, and to comply with this policy. - See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf<br></div><div class=’innerText’><br><strong>According to CalOPPA we agree to the following:</strong></div><div class=’innerText’>Users can visit our site anonymously</div><div class=’innerText’>Once this privacy policy is created, we will add a link to it on our home page, or as a minimum on the first significant page after entering our website.</div><div class=’innerText’>Our Privacy Policy link includes the word 'Privacy’, and can be easily be found on the page specified above.</div><div class=’innerText’><br>Users will be notified of any privacy policy changes:</div><div class=’innerText’>      <strong>•</strong> On our Privacy Policy Page</div><div class=’innerText’>Users are able to change their personal information:</div><div class=’innerText’>      <strong>•</strong> By emailing us</div><div class=’innerText’><br><strong>How does our site handle do not track signals?</strong></div><div class=’innerText’>We honor do not track signals and do not track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place. </div><div class=’innerText’><br><strong>Does our site allow third party behavioral tracking?</strong></div><div class=’innerText’>It’s also important to note that we do not allow third party behavioral tracking</div><span id=’coppAct’></span><br><div class=’blueText’><strong>COPPA (Children Online Privacy Protection Act)</strong></div><br /><div class=’innerText’>When it comes to the collection of personal information from children under 13, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, the nation’s consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online.<br><br></div><div class=’innerText’>We market to<div class=’innerText’>We do not collect information from children under 13</div> children under 13.</div><div class=’innerText’>No</div><div class=’innerText’><br><strong>In order to remove your child’s information please contact the following personnel: </strong></div><div class=’innerText’><br><strong>We adhere to the following COPPA tenants: </strong></div><div class=’innerText’>      <strong>•</strong> Parents can review, delete, manage or refuse with whom their child’s information is shared through contacting us directly.</div> or contacting us directly.</div><br><span id=’ftcFip’></span><br><div class=’blueText’><strong>Fair Information Practices</strong></div><br /><div class=’innerText’>The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.<br><br></div><div class=’innerText’><strong>In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur:</strong></div><div class=’innerText’>We will notify the users via email</div><div class=’innerText’>      <strong>•</strong> Within 1 business day</div><div class=’innerText’>We will notify the users via in site notification</div><div class=’innerText’>      <strong>•</strong> Within 1 business day</div><div class=’innerText’><br>We also agree to the individual redress principle, which requires that individuals have a right to pursue legally enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or a government agency to investigate and/or prosecute non-compliance by data processors.</div><span id=’canSpam’></span><br><div class=’blueText’><strong>CAN SPAM Act</strong></div><br /><div class=’innerText’>The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.<br><br></div><div class=’innerText’><strong>We collect your email address in order to:</strong></div><div class=’innerText’><br><strong>To be in accordance with CANSPAM we agree to the following:</strong></div><div class=’innerText’><strong><br>If at any time you would like to unsubscribe from receiving future emails, you can</strong></div> and we will promptly remove you from <strong>ALL</strong> correspondence.</div><br><span id=’ourCon’></span><br><div class=’blueText’><strong>Contacting Us</strong></div><br /><div class=’innerText’>If there are any questions regarding this privacy policy you may contact us using the information below.<br><br></div><div class=’innerText’>funchayat.in</div> <div class=’innerText’></div> <div class=’innerText’></div> <div class=’innerText’></div> <div class=’innerText’></div><div class=’innerText’>[email protected]</div> <div class=’innerText’></div></div>

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907