Tag
#windows
PES Pro CMS version 1.9.7 suffers from an add administrator vulnerability.
KesionCMS X version 9.5 suffers from an unauthenticated add administrator vulnerability.
Pannres-Idence CMS version 7.3 suffers from a cross site request forgery vulnerability.
Ormesson-Immobilier CMS version 8 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
osCommerce version 4 suffers from a local file inclusion vulnerability.
WordPress theme Workreap version 2.2.2 suffers from a remote shell upload vulnerabilities.
Categories: News Tags: week in security A list of topics we covered in the week of June 5 to June 11 of 2023 (Read more...) The post A week in security (June 5 - 11) appeared first on Malwarebytes Labs.
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 2 and June 9. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key
A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some unknown functionality of the file /changeimage.php of the component Profile Picture Handler. The manipulation of the argument newpic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231176.
A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.