Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Critical VMware Bug Exploits Continue, as Botnet Operators Jump In

A critical VMware bug tracked as CVE-2022-22954 continues to draw cybercriminal moths to its remote code-execution flame, with recent attacks focused on botnets and Log4Shell.

DARKReading
#vulnerability#web#ddos#dos#git#php#backdoor#rce#botnet#vmware#auth#zero_day#sap
FBI: E-Tailers, Beware Web Injections for Scraping Credit-Card Data, Backdoors

Law enforcement is warning about a wave of Web injection attacks on US online retailers that are successfully stealing credit-card information from online checkout pages.

CVE-2022-30054: CVE-nu11secur1ty/vendors/oretnom23/2022/Covid-19-Travel-Pass-Management at main · nu11secur1ty/CVE-nu11secur1ty

In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.

CVE-2022-30052: CVE-nu11secur1ty/vendors/acetech/2022/Home-Clean-Service-System at main · nu11secur1ty/CVE-nu11secur1ty

In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.

CVE-2022-29436: Code Snippets Extended

Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).

New Sysrv-k Botnet Infecting Windows and Linux Systems with Cryptominer

By Deeba Ahmed Microsoft has discovered a new Sysrv botnet variant deploying cryptocurrency miners on Windows and Linux systems. The Microsoft… This is a post from HackRead.com Read the original post: New Sysrv-k Botnet Infecting Windows and Linux Systems with Cryptominer

CVE-2022-30688: security - CVE-2022-30688: needrestart 0.8+ local privilege escalation

needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.

CVE-2022-30072: CVE/CVE-2022-30072.pdf at main · APTX-4879/CVE

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

Online Discussion Forum Site 1.0 SQL Injection

Online Discussion Forum Site version 1.0 suffers from a remote blind SQL injection vulnerability.

OpenCart So Listing Tabs 2.2.0 Unsafe Deserialization

OpenCart So Listing Tabs component versions 2.2.0 and below suffer from a deserialization vulnerability that can allow for arbitrary file writes.