Chamilo 1.11.18 Command Injection Exploit

This Metasploit module exploits an unauthenticated remote command execution vulnerability that affects Chamilo versions 1.11.18 and below. Due to a functionality called Chamilo Rapid to easily convert ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Chamilo unauthenticated command injection in PowerPoint upload

Chamilo is an e-learning platform, also called Learning Management Systems (LMS). This module exploits an unauthenticated remote command execution vulnerability that affects Chamilo versions `1.11.18` ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Chamilo 1.11.18 Command Injection

Post ContentRead More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

PHP vulnerabilities

## Releases * Ubuntu 23.04 * Ubuntu 22.04 LTS ## Packages * php8.1 - HTML-embedded scripting language interpreter It was discovered that PHP incorrectly handled certain XML files. An attacker co ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

php: Fix of 2 CVEs

- CVE-2023-3823: Fix external entity loading in XML without enabling by sanitizing libxml2 globals before parsing - CVE-2023-3824: Fix buffer mismanagement in phar_dir_read()Read More ...

Continue Reading
CVE-2023-38419

An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests.  Note: Software versions which have reached End of Tec ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-35064

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2023-35998

A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitat ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: