SugarCRM 13.0.1 Server-Side Template Injection

Post ContentRead More ...

Continue Reading
Important: php:8.0 security update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: XML loading external entity without being enabled (CVE-2023-3823) * php: phar Buffer mism ...

Continue Reading
Ubuntu 16.04 LTS / 18.04 LTS / 20.04 LTS : PHP vulnerabilities (USN-4583-1)

The remote Ubuntu 16.04 LTS / 18.04 LTS / 20.04 LTS host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-4583-1 advisory. - In PHP versions 7.2.x below ...

Continue Reading
FujiFilm printer credentials encryption issue fixed

![](https://www.pentestpartners.com/content/uploads/2023/10/fujifilmprintercreds-headline.png) ### TL;DR * Many multi-function printers made by FujiFilm Business Innovation Corporation (Fujifilm) wh ...

Continue Reading
RHEL 9 : fence-agents (RHSA-2023:7378)

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:7378 advisory. Certifi is a curated collection of Root C ...

Continue Reading
SugarCRM 13.0.1 Shell Upload Exploit

SugarCRM versions 13.0.1 and below suffer from a remote shell upload vulnerability in the set_note_attachment SOAP call.Read More ...

Continue Reading
Important: php security update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: XML loading external entity without being enabled (CVE-2023-3823) * php: phar Buffer mism ...

Continue Reading
SugarCRM 13.0.1 Server-Side Template Injection Exploit

SugarCRM versions 13.0.1 and below suffer from a server-side template injection vulnerability in the GetControl action from the Import module. This issue can be leveraged to execute arbitrary php code ...

Continue Reading

Back to Main

Subscribe for the latest news: