Tag
#php
SPIP version 4.2.9 suffers from a code execution vulnerability.
Online Traffic Offense version 1.0 suffers from a cross site request forgery vulnerability.
Penglead version 2.0 suffers from a cross site scripting vulnerability.
PPDB version 2.4-update 6118-1 suffers from a cross site request forgery vulnerability.
Online Travel Agency System version 1.0 suffers from an arbitrary file upload vulnerability.
The threat of VBA macros has diminished since Microsoft prevented the execution of macros in Microsoft Office documents downloaded from the internet, but not all users are using the latest up-to-date Office versions and can still be vulnerable.
Zero day remote root exploit for IntelliNet version 2.0. It affects multiple devices of AES Corp and Siemens. The exploit provides a remote shell and escalates your permissions to full root permissions by abusing exec_suid. No authentication needed at all, neither any interaction from the victim. The firmware affected by this exploit runs on fire alarms, burglar sensors and environmental devices, all on the internet, all vulnerable, no patch. Full control over hardware and software with no restrictions, you can manipulate battery voltage and even damage the hardware with unknown outcomes.
Online Musical Instrument Shop IN version 1.0 suffers from a cross site scripting vulnerability.
Online Job Portal IN version 1.0 suffers from a remote SQL injection vulnerability.
Debian Linux Security Advisory 5763-1 - William Khem-Marquez discovered that Pymatgen, a Python library for materials analysis, could be tricked into running arbitrary code if a malformed CIF file is processed.