Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Threat Source newsletter (Nov. 3, 2022): Mastadon, evolution, and LiveJournal oh my!

Welcome to this week’s edition of the Threat Source newsletter. I’m fascinated by how things live and die on the internet. Things that are ubiquitous to our daily lives are simply gone the next. LiveJournal and Myspace we hardly knew you. Elon Musk’s purchase

TALOS
#sql#vulnerability#web#ios#cisco#git#intel#vmware#auth#ssl
CVE-2022-43061: Cve_report/RCE-1.md at main · YorkLee53645349/Cve_report

Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-43062: Cve_report/SQLi-1.md at main · YorkLee53645349/Cve_report

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.

CVE-2022-43063: Cve_report/SQLi-2.md at main · YorkLee53645349/Cve_report

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.

GHSA-236j-rfx5-wq38: OpenCart allows users on admin page to obtain database information or read server files through SQL injection

OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.

CVE-2020-22818: MKCMS V6.2 has mutilple vulnerabilities

MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.

CVE-2021-37823: SQL injection exists in the background of OpenCart - Extrader - Medium

OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.

CVE-2021-37823: SQL injection exists in the background of OpenCart - Extrader - Medium

OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.

CVE-2022-39323: SQL Injection on REST API

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been patched, please upgrade to version 10.0.4. As a workaround, disable login with user_token on API Rest.

Hacker Charged With Extorting Online Psychotherapy Service

A 25-year-old Finnish man has been charged with extorting a once popular and now-bankrupt online psychotherapy company and its patients. Finnish authorities rarely name suspects in an investigation, but they were willing to make an exception for Julius "Zeekill" Kivimaki, a notorious hacker who -- at the tender age of 17 -- had been convicted of more than 50,000 cybercrimes, including data breaches, payment fraud, operating botnets, and calling in bomb threats.