Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

POS Codekop 2.0 Shell Upload

POS Codekop version 2.0 suffers from a remote shell upload vulnerability.

Packet Storm
#vulnerability#web#windows#apple#linux#git#php#rce#auth#chrome#webkit
DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

The threat actors behind the DDoSia attack tool have come up with a new version that incorporates a new mechanism to retrieve the list of targets to be bombarded with junk HTTP requests in an attempt to bring them down. The updated variant, written in Golang, "implements an additional security mechanism to conceal the list of targets, which is transmitted from the [command-and-control] to the

CVE-2023-3133: Tutor LMS – eLearning and online course solution

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.

AppleZeed CMS 2.0 SQL Injection

AppleZeed CMS version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

ApPHP MicroCMS 1.0.1 Host Header Injection

ApPHP MicroCMS version 1.0.1 re-embeds arbitrary content from the client into web pages.

ApnaTrademark CMS 2.5 SQL Injection

ApnaTrademark CMS version 2.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Allhandsmarketing CMS 3.01 SQL Injection

Allhandsmarketing CMS version 3.01 suffers from a remote SQL injection vulnerability.

Allhandsmarketing LMS 2.0 Cross Site Request Forgery

Allhandsmarketing LMS version 2.0 suffers from a cross site request forgery vulnerability.

Advanced HRM 1.6 Insecure Direct Object Reference

Advanced HRM version 1.6 allows for the reseting of the administrative password.