Tag
#php
The BMS/BAS controller suffers from an arbitrary file deletion vulnerability. Input passed to the 'file' parameter in 'databasefiledelete.php' is not properly sanitised before being used to delete files. This can be exploited by an unauthenticated attacker to delete files with the permissions of the web server using directory traversal sequences passed within the affected POST parameter.
Registration and Login System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
SPIP BigUp version 4.3.1 suffers from a remote PHP code injection vulnerability.
RecipePoint version 1.9 suffers from an ignored default credential vulnerability.
A hacktivist group known as Twelve has been observed using an arsenal of publicly available tools to conduct destructive cyber attacks against Russian targets. "Rather than demand a ransom for decrypting data, Twelve prefers to encrypt victims' data and then destroy their infrastructure with a wiper to prevent recovery," Kaspersky said in a Friday analysis. "The approach is indicative of a
BlackNET version 3.7.0.0 appears to allow unauthenticated access to modify data and suffers from arbitrary file deletion and directory traversal vulnerabilities while authenticated.
SPIP BigUp version 4.2.15 suffers from a remote PHP code injection vulnerability.
Taskhub version 3.0.3 suffers from an ignored default credential vulnerability.
Teacher Subject Allocation Management System version 1.0 suffers from a cross site scripting vulnerability.
WordPress LMS plugin versions 4.2.7 and below suffer from a remote SQL injection vulnerability.