Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

BQE Web Suite Billing App Rigged to Inflict Ransomware

An SQL-injection bug in the BQE Web Suite billing app has not only leaked sensitive information, it’s also let malicious actors execute code and deploy ransomware.

Threatpost
#Cloud Security#InfoSec Insider#Vulnerabilities#vulnerability#Breach#Web Security#Sponsored#Vulnerabilities#Malware#Web Security#microsoft#Malware#Web Security#Malware#Mobile Security#Web Security#android#Cloud Security#Critical Infrastructure#InfoSec Insider#Mobile Security#Vulnerabilities#Web Security#Malware#Web Security#Hacks#Malware#Vulnerabilities#Web Security#sql#web
BillQuick Billing App Rigged to Inflict Ransomware

An SQL-injection bug in the BillQuick billing app has not only leaked sensitive information, it’s also let malicious actors execute code and deploy ransomware.

Ubuntu Security Notice USN-5123-2

Ubuntu Security Notice 5123-2 - USN-5123-1 fixed several vulnerabilities in MySQL. This update provides the corresponding update for Ubuntu 16.04 ESM. Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.27 in Ubuntu 20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. Ubuntu 18.04 LTS has been updated to MySQL 5.7.36. Various other issues were also addressed.

Gestionale Open 11.00.00 Privilege Escalation

Gestionale Open version 11.00.00 suffers from a local privilege escalation vulnerability.

Ubuntu Security Notice USN-5123-1

Ubuntu Security Notice 5123-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.27 in Ubuntu 20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. Ubuntu 18.04 LTS has been updated to MySQL 5.7.36. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed.

WordPress 4.9.6 Arbitrary File Deletion

WordPress version 4.9.6 arbitrary file deletion exploit. Original discovery of this vulnerability is attributed to VulnSpy in June of 2018.

WordPress Ninja Tables 4.1.7 Cross Site Scripting

WordPress Ninja Tables plugin version 4.1.7 suffers from a persistent cross site scripting vulnerability.

Botan C++ Crypto Algorithms Library 2.18.2

Botan is a C++ library of cryptographic algorithms, including AES, DES, SHA-1, RSA, DSA, Diffie-Hellman, and many others. It also supports X.509 certificates and CRLs, and PKCS #10 certificate requests, and has a high level filter/pipe message processing system. The library is easily portable to most systems and compilers, and includes a substantial tutorial and API reference. This is the current stable release.

FreeSWITCH 1.10.6 Missing SIP MESSAGE Authentication

FreeSWITCH versions 1.10.6 and below fails to authenticate SIP MESSAGE requests, leading to spam and message spoofing vulnerabilities.