Tag
#php
Hospital Management System version 1.0 suffers from insecure direct object reference and account takeover vulnerabilities.
Hospital Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
Hospital Management System version 1.0 suffers from a remote SQL injection vulnerability.
Automatic-Systems SOC FL9600 FastLine version V06 suffers from a directory traversal vulnerability.
Talos has observed a phishing spam campaign targeting potential victims in Mexico, luring users to download a new obfuscated information stealer we’re calling TimbreStealer, which has been active since at least November 2023.
By Waqas LockBit ransomware gang relaunches operation after law enforcement hacked its servers, threatening to target government entities more now. This is a post from HackRead.com Read the original post: LockBit Ransomware Gang Returns, Taunts FBI and Vows Data Leaks
### TL;DR This vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. The attack requires user interaction by another user or visitor and *cannot* be automated. ---- ### Introduction Unrestricted upload of files with a dangerous type is a type of vulnerability that allows to circumvent expectations and protections in the server setup or backend code. Uploaded files are not checked for their compliance with the intended purpose of the upload target, which can introduce secondary attack vectors. While the vulnerability described here does *not* allow critical attacks like remote code execution (RCE), it can still be abused to upload unexpected file types that could for example make it possible to perform cross-site scripting (XSS) attacks. ### Impact Users with Panel access can upload a user avatar in their own account view. This avatar is intended to be an image, however the file type or file extension was not validat...
Simple Inventory Management System version 1.0 suffers from a remote SQL injection vulnerability.
Flashcard Quiz App version 1.0 suffers from a remote SQL injection vulnerability.
FAQ Management System version 1.0 suffers from a remote SQL injection vulnerability.