Security
Headlines
HeadlinesLatestCVEs

Tag

#php

GHSA-vm6r-j788-hjh5: Contao affected by remote command execution through file upload

### Impact Back end users with access to the file manager can upload malicious files and execute them on the server. ### Patches Update to Contao 4.13.49, 5.3.15 or 5.4.3. ### Workarounds Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory. ### References https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads ### For more information If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose). ### Credits Thanks to Jakob Steeg from usd AG for reporting this vulnerability.

ghsa
#vulnerability#web#git#php#auth
Ship Ferry Ticket Reservation System 1.0 SQL Injection

Ship Ferry Ticket Reservation System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Reservation Management System 1.0 Cross Site Request Forgery

Reservation Management System version 1.0 suffers from a cross site request forgery vulnerability.

Online Job Recruitment Portal Project 1.0 Arbitrary File Upload

Online Job Recruitment Portal Project version 1.0 suffers from an arbitrary file upload vulnerability.

Emergency Ambulance Hiring Portal 1.0 SQL Injection

Emergency Ambulance Hiring Portal version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

ManageEngine DeviceExpert 5.9.7 Build 5970 Hash Disclosure

ManageEngine DeviceExpert version 5.9.7 build 5970 allows for usernames and salted MD5 password hashes to be disclosed.

COVID19 Testing Management System 1.0 Insecure Settings

COVID19 Testing Management System version 1.0 suffers from an ignored default credential vulnerability.

BP Monitoring Management System 1.0 SQL Injection

BP Monitoring Management System version 1.0 version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.