Tag
#firefox
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
WordPress Stafflist plugin version 3.1.2 suffers from a cross site scripting vulnerability.
Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.
WordPress Stafflist plugin version 3.1.2 suffers from a cross site request forgery vulnerability.
WordPress Stafflist plugin version 3.1.2 suffers from a remote SQL injection vulnerability.
The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between April 22 and April 29. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral... [[ This is only the beginning! Please visit the blog for the complete entry ]]
Plus: Microsoft patched some 100 flaws, while Oracle issued more than 500 security fixes.
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.