Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2022-30599: SQL injection risk in badge award criteria

A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

CVE
#sql#vulnerability#git
CVE-2022-30600: Failed login attempts counted incorrectly

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

Microsoft Flags Attack Targeting SQL Servers With Novel Approach

Attackers appear to have found a way around PowerShell monitoring by using a default utility instead.

RHSA-2022:4623: Red Hat Security Advisory: Red Hat build of Quarkus 2.7.5 release and security update

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-3914: smallrye-health-ui: persistent cross-site scripting in endpoint * CVE-2021-22569: protobuf-java: potential DoS in the parsing procedure for binary data * CVE-2021-29427: gradle: repository content filters do not work in Settings pluginManagement * CVE-2021-29428: gradle: local privilege escalation through system temporary directory * CVE-202...

Hackers Gain Fileless Persistence on Targeted SQL Servers Using a Built-in Utility

Microsoft on Tuesday warned that it recently spotted a malicious campaign targeting SQL Servers that leverages a built-in PowerShell binary to achieve persistence on compromised systems. The intrusions, which leverage brute-force attacks as an initial compromise vector, stand out for their use of the utility "sqlps.exe," the tech giant said in a series of tweets. The ultimate goals of the

CVE-2022-30054: CVE-nu11secur1ty/vendors/oretnom23/2022/Covid-19-Travel-Pass-Management at main · nu11secur1ty/CVE-nu11secur1ty

In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.

CVE-2022-30052: CVE-nu11secur1ty/vendors/acetech/2022/Home-Clean-Service-System at main · nu11secur1ty/CVE-nu11secur1ty

In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.

CVE-2022-30053: CVE-nu11secur1ty/vendors/oretnom23/2022/Toll-Tax-Management-System at main · nu11secur1ty/CVE-nu11secur1ty

In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.

CVE-2022-29581: 🐧🕺

Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

Ubuntu Security Notice USN-5424-1

Ubuntu Security Notice 5424-1 - It was discovered that OpenLDAP incorrectly handled certain SQL statements within LDAP queries in the experimental back-sql backend. A remote attacker could possibly use this issue to perform an SQL injection attack and alter the database.