Tag
#apple
Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a password.
On newer macOS/iOS versions, entitlements in binary signature blobs are stored in the DER format. libCoreEntitlements.dylib is the userspace library for parsing and querying such entitlements. The kernel has its own version of this library inside the AppleMobileFileIntegrity module. libCoreEntitlements exposes several functions, such as, for example, to convert entitlements to a dictionary representation (e.g. CEQueryContextToCFDictionary) or to query a specific entitlement (CEContextQuery). Unfortunately, different functions traverse the DER structure in a subtly different way, which allows one API to see one set of entitlements and another API to see a different set of entitlements.
WebKit suffers from a RenderMathMLToken use-after-free vulnerability in CSSCrossfadeValue::crossfadeChanged.
WordPress Slider Revolution plugin versions 4.x.x suffer from a remote shell upload vulnerability.
WordPress Slider Revolution plugin version 4.9.2 suffers from a directory traversal vulnerability.
WordPress Slider Revolution plugin version 4.1.3 suffers from a directory traversal vulnerability.
WordPress Slider Revolution plugin version 4.1.2 suffers from a directory traversal vulnerability.
WordPress Slider Revolution plugin version 3.0.8 suffers from a directory traversal vulnerability.
WordPress Profile Builder plugin version 3.0.5 suffers from a remote SQL injection vulnerability.
Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php.