CVE-2022-42732 - Severe File Exposure in Siemens syngo Dynamics – Deep Dive & Exploit Guide
In late 2022, Siemens disclosed a critical vulnerability (CVE-2022-42732) in their syngo Dynamics product, widely used by healthcare providers to manage cardiovascular imaging
CVE-2022-4051 Hostel Searching Project has a critical vulnerability involving unknown code. The manipulation of the argument property_id leads to sql injection.
The attacker needs to be in contact with the victim in order to exploit this vulnerability. The victim does not have to visit a specific
CVE-2022-44384 An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code.
This issue is due to the fact that the rConfig v3.9.6 package does not check the file extension of the uploaded file before
CVE-2022-42187 - XSS Vulnerability in Hustoj 22.09.22 – Exploit Details and Code Walkthrough
In September 2022, a Cross-Site Scripting (XSS) vulnerability was discovered in Hustoj, a popular open-source Online Judge platform (version 22.09.22). The
CVE-2022-44006 An issue was found in BACKCLICK 5.9.63, which has a validating and sanitizing issue that allows uploading files to unintended locations.
For example, a user uploads a PHP code file named “ calc.php” and another user with write access to that directory could overwrite that file
Episode
00:00:00
00:00:00