Tag
#php
Reservation Management System version 1.0 suffers from a backup disclosure vulnerability.
Rail Pass Management System version 1.0 suffers from an ignored default credential vulnerability.
PreSchool Enrollment System version 1.0 suffers from an ignored default credential vulnerability.
PHP SPM version 1.0 suffers from a cross site request forgery vulnerability.
The ABB BMS/BAS controller suffers from a remote code execution vulnerability. The vulnerable uploadFile() function in bigUpload.php improperly reads raw POST data using the php://input wrapper without sufficient validation. This data is passed to the fwrite() function, allowing arbitrary file writes. Combined with an improper sanitization of file paths, this leads to directory traversal, allowing an attacker to upload malicious files to arbitrary locations. Once a malicious file is written to an executable directory, an authenticated attacker can trigger the file to execute code and gain unauthorized access to the building controller.
The BMS/BAS controller suffers from an arbitrary file deletion vulnerability. Input passed to the 'file' parameter in 'databasefiledelete.php' is not properly sanitised before being used to delete files. This can be exploited by an unauthenticated attacker to delete files with the permissions of the web server using directory traversal sequences passed within the affected POST parameter.
Registration and Login System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
SPIP BigUp version 4.3.1 suffers from a remote PHP code injection vulnerability.
RecipePoint version 1.9 suffers from an ignored default credential vulnerability.
A hacktivist group known as Twelve has been observed using an arsenal of publicly available tools to conduct destructive cyber attacks against Russian targets. "Rather than demand a ransom for decrypting data, Twelve prefers to encrypt victims' data and then destroy their infrastructure with a wiper to prevent recovery," Kaspersky said in a Friday analysis. "The approach is indicative of a