Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2020-35539: Data Manipulation with X-Forwarded-For header at WordPress

A flaw was found in Wordpress 5.1. "X-Forwarded-For" is a HTTP header used to carry the client's original IP address. However, because these headers may very well be added by the client to the requests, if the systems/devices use IP addresses which decelerate at X-Forwarded-For header instead of original IP, various issues may be faced. If the data originating from these fields is trusted by the application developers and processed, any authorization checks originating IP address logging could be manipulated.

CVE
#vulnerability#web#wordpress#php#auth
MiniDVBLinux 5.4 Arbitrary File Read

MiniDVBLinux versions 5.4 and below suffer from an arbitrary file disclosure vulnerability.

RRX IOB LP 1.0 DNS Cache Snooping

RRX IOB LP version 1.0 suffers from a DNS cache snooping vulnerability.

MiniDVBLinux 5.4 Remote Root Command Execution

MiniDVBLinux version 5.4 suffers from an OS command execution vulnerability. This can be exploited to execute arbitrary commands as root through the command GET parameter in /tpl/commands.sh.

WiFi File Transfer 1.0.8 Cross Site Scripting

WiFi File Transfer version 1.0.8 suffers from a cross site scripting vulnerability.

MiniDVBLinux 5.4 Remote Root Command Injection

MiniDVBLinux version 5.4 suffers from an OS command injection vulnerability. This can be exploited to execute arbitrary commands with root privileges.

pfSense pfBlockerNG 2.1.4_26 Shell Upload

This Metasploit module leverages a remote shell upload vulnerability in pfSense pfBlockerNG plugin versions 2.1.4_26 and below. Note that version 3.x is unaffected.

MiniDVBLinux 5.4 Unauthenticated Stream Disclosure

MiniDVBLinux versions 5.4 and below suffer from an unauthenticated live stream disclosure when /tpl/tv_action.sh is called and generates a snapshot in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).

MiniDVBLinux 5.4 Change Root Password

MiniDVBLinux versions 5.4 and below root password changing proof of concept exploit.