Security
Headlines
HeadlinesLatestCVEs

Tag

#firefox

Global Domains International 2.0 HTML Injection

Global Domains International version 2.0 suffers from an html injection vulnerability.

Packet Storm
#vulnerability#windows#google#auth#firefox
GetSimple CMS 3.3.2 Cross Site Scripting

GetSimple CMS version 3.3.2 suffers from a cross site scripting vulnerability.

G And G Corporate CMS 1.0 SQL Injection

G and G Corporate CMS version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

GEN Security+ 4.0 Cross Site Scripting

GEN Security+ version 4.0 suffers from a cross site scripting vulnerability.

Geeklog 2.1.0b1 SQL Injection

Geeklog version 2.1.0b1 suffers from a remote SQL injection vulnerability.

FlightPath LMS 5.0-rc2 Insecure Direct Object Reference

FlightPath LMS version 5.0-rc2 suffers from an insecure direct object reference vulnerability.

FAST TECH CMS 1.0 Cross Site Request Forgery

FAST TECH CMS version 1.0 suffers from a cross site request forgery vulnerability.

doorGets CMS 12 Shell Upload

doorGets CMS version 12 suffers from a remote shell upload vulnerability.

Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT

This is the third documented campaign attributed to this actor in less than a year, with the actor reusing the same infrastructure throughout these operations.