Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Over 4,500 WordPress Sites Hacked to Redirect Visitors to Sketchy Ad Pages

A massive campaign has infected over 4,500 WordPress websites as part of a long-running operation that's been believed to be active since at least 2017. According to GoDaddy-owned Sucuri, the infections involve the injection of obfuscated JavaScript hosted on a malicious domain named "track[.]violetlovelines[.]com" that's designed to redirect visitors to unwanted sites. The latest operation is

The Hacker News
#web#google#microsoft#git#java#wordpress#php#chrome#firefox#The Hacker News
Cacti 1.2.22 Command Injection

This Metasploit module exploits an unauthenticated command injection vulnerability in Cacti versions through 1.2.22 in order to achieve unauthenticated remote code execution as the www-data user.

Inout Search Engine 10.1.3 Cross Site Scripting

Inout Search Engine version 10.1.3 suffers from a cross site scripting vulnerability.

Inout Homestay 2.2 SQL Injection

Inout Homestay version 2.0 suffers from a remote SQL injection vulnerability.

CVE-2022-45639: Binary World - Informazioni,Sicurezza informatica,Sorgenti e tanto altro...

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.

CVE-2023-22630: IzyBat Orange casiers - SQLi injection

IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.

CVE-2022-46639: Ia Informática - Contatta con IA Informatica a Valencia.

A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.

CVE-2023-0447: Changeset 2844200 for youtube-channel – WordPress Plugin Repository

The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_all_cache function in versions up to, and including, 3.0.12.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to clear the plugin's cache.

Ubuntu Security Notice USN-5818-1

Ubuntu Security Notice 5818-1 - It was discovered that PHP incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code.

Inout RealEstate 2.1.3 SQL Injection

Inout RealEstate version 2.1.3 suffers from a remote SQL injection vulnerability.