#commandinjection — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #commandinjection, aggregated by home.social.
-
PHP Composer Flaws Expose Code Execution Risk, Prompting Patches
Critical flaws in PHP Composer, a popular package manager, leave countless websites vulnerable to code execution attacks - but fortunately, patches have been released to swiftly mitigate this risk. If exploited, these high-severity vulnerabilities could allow hackers to execute arbitrary commands, putting entire…
#PhpComposer #CodeExecution #PackageManager #CommandInjection #VulnerabilityManagement
-
Missing a firmware update on your TP-Link Omada gateway could be like leaving your front door wide open—hackers can run commands on your network with ease. Is your business protected?
#tp-link
#commandinjection
#networksecurity
#firmwareupdate
#cybersecurityrisks -
Critical Figma MCP Server Flaw Allows Remote Code Execution https://dailydarkweb.net/critical-figma-mcp-server-flaw-allows-remote-code-execution/ #RemoteCodeExecution #DeveloperSecurity #commandinjection #Vulnerability #CyberSecurity #vulnerability #CVE202553967 #Figma #patch #MCP #RCE
-
Kolejny problem Fortineta – podatne FortiSIEM pod ostrzałem
Mamy wrażenie, że nie tylko nas zaczynają nużyć problemy produktów bezpieczeństwa, zwłaszcza od kilku firm… . Tym razem legendarny badacz SinSinology prezentuje krytyczną podatność (9.8 w skali CVSS w biuletynie bezpieczeństwa producenta) w produkcie dedykowanym dużym organizacjom – FortiSIEM. TLDR: Sprawa nie jest błaha, ponieważ jak informuje Fortinet luka ta...
#WBiegu #CommandInjection #Fortinet #Podatność #Rce #Siem #Websec
https://sekurak.pl/kolejny-problem-fortineta-podatne-fortisiem-pod-ostrzalem/
-
Zdalne wykonanie kodu bez uwierzytelnienia na Centosie – panel CWP
CentOS Web Panel to darmowe rozwiązanie dostępne na systemach z rodziny CentOS (lub korzystających z RPM), składające się właściwie z dwóch elementów. Oferuje interfejs administratorski do zarządzania serwerem, konfiguracji usług takich jak serwery WWW, poczty e-mail czy DNS. Oprócz tego, na innym porcie udostępniany jest drugi panel dla użytkowników końcowych,...
#WBiegu #Authbypass #Centos #CommandInjection #Cwp #Rce #Websec
https://sekurak.pl/zdalne-wykonanie-kodu-bez-uwierzytelnienia-na-centosie-panel-cwp/
-
CERT-IN Warns About Critical Vulnerabilities in Palo Alto Networks Applications https://thecyberexpress.com/cert-in-vulnerabilities-palo-alto-networks/ #informationdisclosure #privilegeescalation #TheCyberExpressNews #CybersecurityNews #commandinjection #paloaltonetworks #securityadvisory #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #GlobalProtect #CortexXSOAR #CERTIn #PANOS
-
CERT-IN Warns About Critical Vulnerabilities in Palo Alto Networks Applications https://thecyberexpress.com/cert-in-vulnerabilities-palo-alto-networks/ #informationdisclosure #privilegeescalation #TheCyberExpressNews #CybersecurityNews #commandinjection #paloaltonetworks #securityadvisory #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #GlobalProtect #CortexXSOAR #CERTIn #PANOS
-
Linksys Router Flaw Let Attackers Perform Command Injection, PoC Released https://gbhackers.com/linksys-router-flaw-command-injection/ #VulnerabilityAnalysis #CVE/vulnerability #CyberSecurityNews #CommandInjection #LinksysRouter #Vulnerability #Exploit
-
Palo Alto Networks #GlobalProtect 0day exploited since at least March 26 - https://www.bleepingcomputer.com/news/security/palo-alto-networks-zero-day-exploited-since-march-to-backdoor-firewalls/ #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400
-
CVE-2024-3400 PAN-OS: OS Command Injection #Vulnerability in #GlobalProtect Gateway
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
This issue will be fixed in hotfix releases of PAN-OS 10.2.9-h1 (ETA: By 4/14), PAN-OS 11.0.4-h1 (ETA: By 4/14), and PAN-OS 11.1.2-h3 (ETA: By 4/14), and in all later PAN-OS versions.
ref: https://security.paloaltonetworks.com/CVE-2024-3400 #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362