Security
Headlines
HeadlinesLatestCVEs

Tag

#ssh

News Script Pro 2.4 Cross Site Scripting

News Script Pro version 2.4 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#vulnerability#web#php#auth#ssh
Funeral Script 3.1 Cross Site Scripting

Funeral Script version 3.1 suffers from a cross site scripting vulnerability.

FAQ Script 2.3 Cross Site Scripting

FAQ Script version 2.3 suffers from a cross site scripting vulnerability.

Event Script 2.1 Cross Site Scripting

Event Script version 2.1 suffers from a cross site scripting vulnerability.

Classified Ads Script 1.8 Cross Site Scripting

Classified Ads Script version 1.8 suffers from a cross site scripting vulnerability.

GuestBook Script 2.2 Cross Site Scripting

GuestBook Script version 2.2 suffers from a cross site scripting vulnerability.

Exposed Interfaces in US Federal Networks: A Breach Waiting to Happen

By Waqas The research mainly aimed at examining VPNs, firewalls, access points, routers, and other remote server management appliances used by top government agencies in the United States. This is a post from HackRead.com Read the original post: Exposed Interfaces in US Federal Networks: A Breach Waiting to Happen

Hackers Hiding DcRAT Malware in Fake OnlyFans Content

By Habiba Rashid DcRAT malware includes a ransomware plugin that encrypts non-system files, rendering them inaccessible without the decryption key, which threat actors will likely hold for ransom. This is a post from HackRead.com Read the original post: Hackers Hiding DcRAT Malware in Fake OnlyFans Content

Mockingjay Slips By EDR Tools With Process Injection Technique

By leveraging misconfigured DLLs instead of EDR-monitored APIs, this new technique injects malicious code into running processes, completely evading endpoint security.

CVE-2023-34099: Shopware 5 - Security Updates

Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts. This issue has been addressed in version 5.7.18 and users are advised to update. There are no known workarounds for this vulnerability.