Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3fgr-xjr6-xqm8: code injection in phpxmlrpc/phpxmlrpc

code injection in Wrapper::buildClientWrapperCode via manipulation of the $client argument. It was possible to force the client to access local files or connect to undesired urls instead of the intended target server’s url.

ghsa
#git#php

code injection in phpxmlrpc/phpxmlrpc

High severity GitHub Reviewed Published Nov 28, 2022

ghsa: Latest News

GHSA-3m86-c9x3-vwm9: Graylog vulnerable to privilege escalation through API tokens