Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

VICIdial 2.14-917a Remote Code Execution

An attacker with authenticated access to VICIdial version 2.14-917a as an agent can execute arbitrary shell commands as the root user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

Packet Storm
#sql#vulnerability#web#ios#mac#linux#js#git#php#rce#perl#auth#telnet
VICIdial 2.14-917a SQL Injection

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial version 2.14-917a to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

Red Hat Security Advisory 2024-6536-03

Red Hat Security Advisory 2024-6536-03 - Red Hat AMQ Streams 2.5.2 is now available from the Red Hat Customer Portal. Issues addressed include bypass, denial of service, information leakage, and memory leak vulnerabilities.

Red Hat Security Advisory 2024-6529-03

Red Hat Security Advisory 2024-6529-03 - An update for dovecot is now available for Red Hat Enterprise Linux 9. Issues addressed include denial of service and resource exhaustion vulnerabilities.

Queuing Simple Chatbot 1.0 Shell Upload

Queuing Simple Chatbot version 1.0 suffers from a remote shell upload vulnerability.

Profiling System 1.0 Shell Upload

Profiling System version 1.0 suffers from a remote shell upload vulnerability.

Passion Responsive Blogging 1.0 Cross Site Scripting

Passion Responsive Blogging version 1.0 suffers from a cross site scripting vulnerability.

Online Survey System 1.0 Cross Site Scripting / Remote File Inclusion

Online Survey System version 1.0 suffers from cross site scripting and remote file inclusion vulnerabilities.

Online Birth Certificate System 1.0 Insecure Settings

Online Birth Certificate System version 1.0 suffers from an ignored default credential vulnerability.

Medical Card Generations System 1.0 Insecure Settings

Medical Card Generations System version 1.0 suffers from an ignored default credential vulnerability.