CVE-2022-45866 The qpress file editor before version 11.3 allows directory traversal via ../ in a .qp file.
Attackers can exploit this vulnerability to inject and execute arbitrary PHP code in the web server’s directory. Percona XtraBackup’s .qp file format is
CVE-2021-43258 - Remote Code Execution in ChurchInfo 1.3. – Simple Exploitation via CartView.php
In November 2021, a dangerous vulnerability was found and published (reference) in ChurchInfo version 1.3.. This open-source church management app allows users to
CVE-2022-39833 - Remote Code Execution in FileCloud via Crafted HTTP Requests
In late 2022, a serious vulnerability was discovered in FileCloud, a popular enterprise file sharing and sync platform. Tracked as CVE-2022-39833, this security
CVE-2022-41922 - yiisoft/yii (Yii 1.x) Remote Code Execution via unserialize() – Exploit Details and Fix
Summary:
A serious security flaw, CVE-2022-41922, was identified in the popular PHP framework Yii 1.x (yiisoft/yii). If your application uses Yii
CVE-2021-35284 - SQL Injection in get_user Function of rizalafani cms-php v1 - Deep Dive and Exploit
In this post, we'll explore the SQL Injection vulnerability identified as CVE-2021-35284 in the get_user function of the login_manager.
Episode
00:00:00
00:00:00