Tag: injection
-
SQL injection vulnerability in Fortinet software under attack
Fortinet and CISA confirmed CVE-2023-48788 is being actively exploited. But the Shadowserver Foundation found that many vulnerable instances remain on… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366575417/SQL-injection-vulnerability-in-Fortinet-software-under-attack
-
Multiple MySQL2 Flaw Let Attackers Arbitrary Code Remotely
The widely used MySQL2 has been discovered to have three critical vulnerabilities: remote Code execution, Arbitrary code injection, and Prototype Poll… First seen on gbhackers.com Jump to article: gbhackers.com/multiple-mysql2-flaws-remote-code-execution/
-
22,500 Palo Alto firewalls possibly vulnerable to ongoing attacks
Approximately 22,500 exposed Palo Alto GlobalProtect firewall devices are likely vulnerable to the CVE-2024-3400 flaw, a critical command injection vu… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/22-500-palo-alto-firewalls-possibly-vulnerable-to-ongoing-attacks/
-
Cisco warns of a command injection escalation flaw in its IMC. PoC publicly available
Cisco has addressed a high-severity vulnerability in its Integrated Management Controller (IMC) for which publicly available exploit code exists. Cisc… First seen on securityaffairs.com Jump to article: securityaffairs.com/161975/hacking/cisco-integrated-management-controller-bug.html
-
Critical ‘BatBadBut’ Rust Vulnerability Exposes Windows Systems to Attacks
A critical security flaw in the Rust standard library could be exploited to target Windows users and stage command injection attacks.The vulnerability… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/critical-batbadbut-rust-vulnerability.html
-
Uncle Sam’s had it up to here with ‘unforgivable’ SQL injection flaws
First seen on theregister.com Jump to article: www.theregister.com/2024/03/26/fbi_cisa_sql_injection/
-
Multiple botnets exploiting one-year-old TP-Link flaw to hack routers
At least six distinct botnet malware operations are hunting for TP-Link Archer AX21 (AX1800) routers vulnerable to a command injection security issue … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/multiple-botnets-exploiting-one-year-old-tp-link-flaw-to-hack-routers/
-
CISA adds Palo Alto Networks PAN-OS Command Injection flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Palo Alto Networks PAN-OS Command Injection flaw to its Known Exploited Vulnerabilit… First seen on securityaffairs.com Jump to article: securityaffairs.com/161855/hacking/palo-alto-networks-pan-os-bug-known-exploited-vulnerabilities-catalog.html
-
Likely State Hackers Exploiting Palo Alto Firewall Zero-Day
Company Released a Hotfix to the Command Injection Vulnerability. Firewall appliance manufacturer Palo Alto Networks rushed out a hotfix Friday to a c… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/likely-state-hackers-exploiting-palo-alto-firewall-zero-day-a-24866
-
Windows Apps Vulnerable to Command Injection via >>BatBadBut<< Flaw
First seen on hackread.com Jump to article: www.hackread.com/windows-batbadbut-vulnerability-comment-injection/
-
92K D-Link NAS Devices Open to Critical Command-Injection Bug
The company is asking users to retire several network-attached storage (NAS) models to avoid compromise through a publicly available exploit that resu… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/92k-dlink-nas-critical-command-injection-bug
-
CVE-2024-3400 exploited: Unit 42, Volexity share more details about the attacks
Earlier today, Palo Alto Networks revealed that a critical command injection vulnerability (CVE-2024-3400) in the company’s firewalls has been exploit… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/12/palo-alto-networks-firewalls-cve-2024-3400-exploited/
-
Palo Alto Networks firewalls under attack, hotfixes incoming! (CVE-2024-3400)
Attackers are exploiting a command injection vulnerability (CVE-2024-3400) affecting Palo Alto Networks’ firewalls, the company has warned, and urged … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/12/cve-2024-3400/
-
BatBadBut flaw allowed an attacker to perform command injection on Windows
A critical vulnerability, named ‘BatBadBut’, impacts multiple programming languages, its exploitation can lead to command injection in Windows applica… First seen on securityaffairs.com Jump to article: securityaffairs.com/161785/security/batbadbut-flaw-programming-languages.html
-
Schwere Sicherheitslücke in WordPress-Plugin Layerslider – SQL-Injection eröffnet Angreifer Zugang zu WordPress
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecke-layerslider-plugin-entdeckt-a-a2f1c11fa3a5fb78c1bd3639abea4a90/
-
LayerSlider Plugin Flaw Exposes 1M Sites To SQL Injections
Recent media reports have revealed a crucial LayerSlider plugin flaw. According to these reports, this flaw has exposed numerous WordPress sites to SQ… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/layerslider-plugin-flaw-exposes-1m-sites-to-sql-injections/
-
Palo Alto Networks warns of PAN-OS firewall zero-day used in attacks
Today, Palo Alto Networks warns that an unpatched critical command injection vulnerability in its PAN-OS firewall is being actively exploited in attac… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-pan-os-firewall-zero-day-used-in-attacks/
-
Palo Alto Networks Warns of Exploited Firewall Vulnerability
Palo Alto Networks warns of limited exploitation of a critical command injection vulnerability leading to code execution on firewalls. The post o Netw… First seen on securityweek.com Jump to article: www.securityweek.com/palo-alto-networks-warns-of-exploited-firewall-vulnerability/
-
‘BatBadBut’ Command Injection Vulnerability Affects Multiple Programming Languages
A critical vulnerability in multiple programming languages allows attackers to inject commands in Windows applications. The post al vulnerability in m… First seen on securityweek.com Jump to article: www.securityweek.com/batbadbut-command-injection-vulnerability-affects-multiple-programming-languages/
-
Command injection attacks likely with critical Rust vulnerability
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/command-injection-attacks-likely-with-critical-rust-vulnerability
-
Rust rustles up fix for 10/10 critical command injection bug on Windows
First seen on theregister.com Jump to article: www.theregister.com/2024/04/10/rust_critical_vulnerability_windows/
-
Critical Security Flaw Exposes 1 Million WordPress Sites to SQL Injection
A researcher received a $5,500 bug bounty for discovering a vulnerability (CVE-2024-2879) in LayerSlider, a plug-in with more than a million active in… First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/critical-security-flaw-wordpress-sql-injection
-
How to Tame SQL Injection
First seen on darkreading.com Jump to article: www.darkreading.com/application-security/tools-and-techniques-to-tame-sql-injection
-
Over 92,000 Internet-facing D-Link NAS devices can be easily hacked
A researcher disclosed an arbitrary command injection and hardcoded backdoor issue in multiple end-of-life D-Link NAS models. A researcher who goes on… First seen on securityaffairs.com Jump to article: securityaffairs.com/161549/hacking/d-link-nas-flaw.html
-
CISA and FBI Issue Alert on SQL Injection Vulnerabilities
SQL injection vulnerabilities, often abbreviated as SQLi, persist as a significant issue in commercial software products. In response to a recent high… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/cisa-and-fbi-issue-alert-on-sql-injection-vulnerabilities/
-
Over 92,000 exposed D-Link NAS devices have a backdoor account
A threat researcher has disclosed a new arbitrary command injection and hardcoded backdoor flaw in multiple end-of-life D-Link Network Attached Storag… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-92-000-exposed-d-link-nas-devices-have-a-backdoor-account/
-
Microsoft Beefs Up Defenses in Azure AI
Microsoft adds tools to protect Azure AI from threats such as prompt injection, as well as to give developers the capabilities to ensure generative AI… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/microsoft-adds-tools-for-protecting-against-prompt-injection-other-threats-in-azure-ai
-
XSS flaw in WordPress WP-Members Plugin can lead to script injection
A cross-site scripting vulnerability (XXS) in the WordPress WP-Members Membership plugin can lead to malicious script injection. Researchers from Defi… First seen on securityaffairs.com Jump to article: securityaffairs.com/161407/hacking/wordpress-wp-members-plugin-xss.html

