Security
Headlines
HeadlinesLatestCVEs

Tag

#google

CVE-2021-45003: Laundry_Booking_Management_RCE – Google Диск

Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.

CVE
#vulnerability#web#google
CVE-2021-46078: GitHub - plsanu/Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Stored-Cross-Site-Scripting: Vehicle Service Management System - 'Multiple' File upload Leads to Stored Cross-Site Scrip

An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability.

CVE-2021-46079: GitHub - plsanu/Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Html-Injection: Vehicle Service Management System - 'Multiple' File upload Leads to Html Injection

An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.

CVE-2022-0121: Exposure of Sensitive Information to an Unauthorized Actor in hoppscotch

hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVE-2021-39143: Build software better, together

Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for deployment without validating the paths in that deployment don't override system files. This would allow an attacker to override files on the container, POTENTIALLY introducing a MITM type attack vector by replacing libraries or injecting wrapper files. Users are advised to update as soon as possible. For users unable to update disable Google AppEngine deployments and/or disable artifacts that provide TARs.