Security
Headlines
HeadlinesLatestCVEs

Tag

#google

Laundry Management System 1.0 Remote File Inclusion

Laundry Management System version 1.0 suffers from a remote file inclusion vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox
File Management System 1.0 Arbitrary File Upload

File Management System version 1.0 suffers from an arbitrary file upload vulnerability.

GHSA-4vvj-4cpr-p986: Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

Hi, Webpack developer team! ### Summary We discovered a DOM Clobbering vulnerability in Webpack’s `AutoPublicPathRuntimeModule`. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name` attribute) are present. We found the real-world exploitation of this gadget in the Canvas LMS which allows XSS attack happens through an javascript code compiled by Webpack (the vulnerable part is from Webpack). We believe this is a severe issue. If Webpack’s code is not resilient to DOM Clobbering attacks, it could lead to significant security vulnerabilities in any web application using Webpack-compiled code. ### Details #### Backgrounds DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) livin...

macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users

Users of Chinese instant messaging apps like DingTalk and WeChat are the target of an Apple macOS version of a backdoor named HZ RAT. The artifacts "almost exactly replicate the functionality of the Windows version of the backdoor and differ only in the payload, which is received in the form of shell scripts from the attackers' server," Kaspersky researcher Sergey Puzan said. HZ RAT was first

miniProxy 1.0.0 Remote File Inclusion

miniProxy version 1.0.0 suffers from a remote file inclusion vulnerability.

Medical Center Portal 1.0 SQL Injection

Medical Center Portal version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Marc@TMS CMS 1.0 SQL Injection

Marc@TMS CMS version 1.0 suffers from a remote SQL injection vulnerability.