Latest News
Ubuntu Security Notice 6978-1 - It was discovered that XStream incorrectly handled parsing of certain crafted XML documents. A remote attacker could possibly use this issue to read arbitrary files. Zhihong Tian and Hui Lu found that XStream was vulnerable to remote code execution. A remote attacker could run arbitrary shell commands by manipulating the processed input stream. It was discovered that XStream was vulnerable to server-side forgery attacks. A remote attacker could request data from internal resources that are not publicly available only by manipulating the processed input stream.
Cybersecurity researchers have uncovered a never-before-seen dropper that serves as a conduit to launch next-stage malware with the ultimate goal of infecting Windows systems with information stealers and loaders. "This memory-only dropper decrypts and executes a PowerShell-based downloader," Google-owned Mandiant said. "This PowerShell-based downloader is being tracked as PEAKLIGHT." Some of
PlantUML version 1.2024.6 suffers from a cross site scripting vulnerability.
Crime Complaints Reporting Management System version 1.0 suffers from a remote shell upload vulnerability.
Courier Management System version 1.0 suffers from a cross site request forgery vulnerability.
Company Visitor Management version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
CMSsite version 1.0 suffers from a remote shell upload vulnerability.
Red Hat Security Advisory 2024-5446-03 - Red Hat OpenShift Container Platform release 4.13.48 is now available with updates to packages and images that fix several bugs and add enhancements. Issues addressed include a memory exhaustion vulnerability.
CMS RIMI version 1.3 suffers from cross site request forgery and arbitrary file upload vulnerabilities.
Client Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.