Tag
Medical Hub Directory Site version 1.0 suffers from an ignored default credential vulnerability.
Medical Center Portal version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Marc@TMS CMS version 1.0 suffers from a remote SQL injection vulnerability.
Lodging Reservation Management System version 1.0 suffers from an ignored default credential vulnerability.
Login System Project version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Google has revealed that a security flaw that was patched as part of a security update rolled out last week to its Chrome browser has come under active exploitation in the wild. Tracked as CVE-2024-7965, the vulnerability has been described as an inappropriate implementation bug in the V8 JavaScript and WebAssembly engine. "Inappropriate implementation in V8 in Google Chrome prior to
We came a cross a clever abuse of Google and Microsoft's services that fooled us for a minute. See if you could have spotted it.
### Impact When using the `Extract()` method of unzip-stream, malicious zip files were able to write to paths they shouldn't be allowed to. ### Patches Fixed in 0.3.2 ### References - https://snyk.io/research/zip-slip-vulnerability - https://github.com/mhr3/unzip-stream/compare/v0.3.1...v0.3.2 ### Credits Justin Taft from Google
This week on the Lock and Code podcast, we speak with Nitya Sharma about why AI is a far bigger concern than malware in staying safe.
Helpdeskz version 2.0.2 suffers from a persistent cross site scripting vulnerability.