Tag
#php
MetaFox versions 5.1.8 and below suffer from a remote shell upload vulnerability.
MSMS-PHP version 1.0 suffers from a remote shell upload vulnerability.
MSMS-PHP version 1.0 suffers from a remote SQL injection vulnerability.
Talos IR has responded to several recent incidents in which threat actors used legitimate digital document publishing sites such as Publuu and Marq to host phishing documents as part of ongoing credential and session harvesting attacks.
NorthStar C2 agent version 1.0 applies insufficient sanitization on agent registration routes, allowing an unauthenticated attacker to send multiple malicious agent registration requests to the teamserver to incrementally build a functioning javascript payload in the logs web page. This cross site scripting payload can be leveraged to execute commands on NorthStar C2 agents.
Human Resource Management System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to Abdulhakim Oner in March of 2023.
RUPPEINVOICE version 1.0 suffers from a remote SQL injection vulnerability.
DataCube3 version 1.0 suffers from a remote shell upload vulnerability.
NDtaskmatic version 1.0 suffers from a remote SQL injection vulnerability.
The Rich Filemanager feature of Artica Proxy versions 4.40 and 4.50 provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user. This provides an unauthenticated attacker complete access to the file system.