Tag
#php
SPA-CART CMS version 1.9.0.3 suffers from a persistent cross site scripting vulnerability.
Petrol Pump Management Software version 1.0 suffers from a remote shell upload vulnerability.
Tourism Management System version 2.0 suffers from a remote shell upload vulnerability.
Google Cloud Run is currently being abused in high-volume malware distribution campaigns, spreading several banking trojans such as Astaroth (aka Guildma), Mekotio and Ousaban to targets across Latin America and Europe. The volume of emails associated with these campaigns has significantly increased since September 2023 and we continue to regularly
A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations. The flaw, tracked as CVE-2024-25600 (CVSS score: 9.8), enables unauthenticated attackers to achieve remote code execution. It impacts all versions of the Bricks up to and including 1.9.6. It has been addressed by the theme developers in&
InstantCMS version 2.16.1 suffers from a persistent cross site scripting vulnerability that appears to require administrative access.
Online Library Management System version 3 suffers from a password reset vulnerability due to a logic flaw of allowing the same email address to be set for multiple users.
Employee Management System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of this finding is attributed to Ozlem Balci in January of 2024.
WonderCMS version 4.3.2 remote exploit that leverages cross site scripting to achieve remote code execution.
User Registration and Login and User Management System version 3.1 suffers from a remote SQL injection vulnerability.