Security
Headlines
HeadlinesLatestCVEs

Tag

#php

GEN Security+ 4.0 Cross Site Scripting

GEN Security+ version 4.0 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#google#php#auth#firefox
Geeklog 2.1.0b1 SQL Injection

Geeklog version 2.1.0b1 suffers from a remote SQL injection vulnerability.

User Registration And Login And User Management System 3.0 Cross Site Scripting

User Registration and Login and User Management System version 3.0 suffers from a persistent cross site scripting vulnerability.

User Registration And Login And User Management System 3.0 SQL Injection

User Registration and Login and User Management System version 3.0 suffers from a remote SQL injection vulnerability.

Uvdesk 1.1.4 Cross Site Scripting

Uvdesk version 1.1.4 suffers from a persistent cross site scripting vulnerability.

FAST TECH CMS 1.0 Cross Site Request Forgery

FAST TECH CMS version 1.0 suffers from a cross site request forgery vulnerability.

doorGets CMS 12 Shell Upload

doorGets CMS version 12 suffers from a remote shell upload vulnerability.

Lazarus Group's infrastructure reuse leads to discovery of new malware

Lazarus Group appears to be changing its tactics, increasingly relying on open-source tools and frameworks in the initial access phase of their attacks, as opposed to strictly employing them in the post-compromise phase.

Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT

This is the third documented campaign attributed to this actor in less than a year, with the actor reusing the same infrastructure throughout these operations.