Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-30708: Webmin

Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.

CVE
#sql#xss#vulnerability#web#ios#android#mac#windows#apple#google#amazon#ubuntu#linux#debian#apache#git#java#php#rce#perl#ldap#samba#pdf#bios#auth#ssh#telnet#ibm#rpm#postgres#ssl
Threat Roundup for May 6 to May 13

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between May 6 and May 13. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,... [[ This is only the beginning! Please visit the blog for the complete entry ]]

CVE-2022-1715: Account Takeover in facturascripts

Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

CVE-2022-1715: Account Takeover in facturascripts

Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

CVE-2022-30401: bug_report/SQLi-14.md at main · k0xx11/bug_report

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.

CVE-2022-30400: bug_report/SQLi-13.md at main · k0xx11/bug_report

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.

CVE-2022-30399: bug_report/SQLi-11.md at main · k0xx11/bug_report

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.

CVE-2022-30398: bug_report/SQLi-10.md at main · k0xx11/bug_report

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.

CVE-2022-30396: bug_report/SQLi-9.md at main · k0xx11/bug_report

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.

CVE-2022-30395: bug_report/SQLi-7.md at main · k0xx11/bug_report

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.