Tag
#php
DBCInfoTech CMS version 2.0 suffers from an unauthenticated administrator reinstall vulnerability.
Education Time Indonesian School CRM version 1.7 suffers from a cross site scripting vulnerability.
Eden CMS version 1.02 suffers from a cross site scripting vulnerability.
Ecommerce Responsive version 1.2 suffers from an insecure direct object reference vulnerability.
E-Biz CMS version 2.0 suffers from a cross site request forgery vulnerability.
EasyPX CMS version 06.02.04 suffers from a cross site scripting vulnerability.
E-commerce sites using Adobe's Magento 2 software are the target of an ongoing campaign that has been active since at least January 2023. The attacks, dubbed Xurum by Akamai, leverage a now-patched critical security flaw (CVE-2022-24086, CVSS score: 9.8) in Adobe Commerce and Magento Open Source that, if successfully exploited, could lead to arbitrary code execution. "The attacker seems to be
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'profile[role]' parameter during a profile update.
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server.