Tag
#sql
Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker developing and deploying eight (8) incremental iterations of their credential harvesting malware while continuing to develop infrastructure for an upcoming (spoiler: now launched) campaign
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals.
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
FoccusWeb CMS version 0.1 suffers from a cross site scripting vulnerability.
Fluent CMS version 1.0.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Color Prediction Game version 1.0 suffers from a remote SQL injection vulnerability.
Global Multi School Management System Express version 1.0 suffers from a remote SQL injection vulnerability.
OVOO Movie Portal CMS version 3.3.3 suffers from a remote SQL injection vulnerability.
Taskhub CRM Tool version 2.8.6 suffers from a remote SQL injection vulnerability.