Security
Headlines
HeadlinesLatestCVEs

Tag

#php

GoldenJackal: New Threat Group Targeting Middle Eastern and South Asian Governments

Government and diplomatic entities in the Middle East and South Asia are the target of a new advanced persistent threat actor named GoldenJackal. Russian cybersecurity firm Kaspersky, which has been keeping tabs on the group's activities since mid-2020, characterized the adversary as both capable and stealthy. The targeting scope of the campaign is focused on Afghanistan, Azerbaijan, Iran, Iraq,

The Hacker News
#vulnerability#web#mac#microsoft#wordpress#php#sap#The Hacker News
WBiz Desk 1.2 Cross Site Scripting

WBiz Desk version 1.2 suffers from a cross site scripting vulnerability.

WBiz Desk 1.2 SQL Injection

WBiz Desk version 1.2 suffers from a remote SQL injection vulnerability in the idtk parameter. This is a variant finding from the original discovery of SQL injection in this version attributed to h4ck3r in May of 2023.

Affiliate Me 5.0.1 SQL Injection

Affiliate Me version 5.0.1 suffers from a remote SQL injection vulnerability.

CVE-2020-20012: CVE

WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

CVE-2023-29919: GitHub - xiaosed/CVE-2023-29919

SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.