Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-36904: security - Multiple vulnerabilities in Jenkins plugins

Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

CVE
#xss#csrf#vulnerability#web#android#mac#windows#google#linux#git#java#php#auth#ssh#rpm#maven
CVE-2022-2550: fix DokuWiki shell issue · hestiacp/hestiacp@3d4c309

OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

CVE-2022-34549: CWE-434: Unrestricted Upload of File with Dangerous Type (4.8)

Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.

IIS extensions are on the rise as backdoors to servers

The Microsoft 365 Defender Research Team has warned that attackers are increasingly leveraging Internet Information Services (IIS) extensions as covert backdoors into servers. The post IIS extensions are on the rise as backdoors to servers appeared first on Malwarebytes Labs.

PrestaShop warns of vulnerability: Update your stores now!

We take a look at a security advisory from PrestaShop which warns of compromised stores and redirected payment data. The post PrestaShop warns of vulnerability: Update your stores now! appeared first on Malwarebytes Labs.

CVE-2022-34594: bug_report/XSS-1.md at master · gitgeniuss/bug_report

Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.

CVE-2022-34611: CVE-report/OFRS.md at main · As4ki/CVE-report

A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.

CVE-2022-34971: File upload command execution at advertising management · Issue #62 · liufee/cms

An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.

Hospital Information System 1.0 SQL Injection

Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Garage Management System 1.0 Shell Upload

Garage Management System version 1.0 suffers from a remote shell upload vulnerability.