#sqlinjection — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sqlinjection, aggregated by home.social.
-
CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now.
#CVE202628576 #Android #SQLInjection #Android17 #ContactsProvider #MobileSecurity #InfoSec #DataLeak #ExploitPoC #Pixel
-
cPanel Flaw Enables Code Execution as Root via Mail Privileges
A critical cPanel security flaw, known as CVE-2026-67401, allows hackers with mail-related privileges to create files on a server and execute code as the root user, putting your entire system at risk. This vulnerability affects every supported version of cPanel and WHM, making it crucial to take immediate action.
-
A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.
#cPanel #SQLInjection #CVE202667401 #Cybersecurity #Vulnerability
-
Ah, the joys of browsing the web in 2023: you try to read about a quirky nuclear thrift store and instead get a front-row seat to Cloudflare's one-man show. 🎭 Maybe if we all chant "SQL injection" three times, it’ll let us in. 🙄🔒
https://www.atlasobscura.com/places/black-hole-of-los-alamos #webbrowsing #Cloudflare #SQLinjection #cybersecurity #techhumor #HackerNews #ngated -
Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.
#Switchvox #CVE20269586 #RCE #SQLInjection #Sangoma #VoIP #InfoSec
https://meterpreter.org/switchvox-cve-2026-9586-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Hackers are actively exploiting a vulnerability in Sangoma Switchvox, CVE-2026-9586, to gain unauthorized access and deploy reverse shells on vulnerable devices, with around 4,000 exposed devices, mostly in the US, at risk. This security flaw allows attackers to inject malicious SQL code, making it crucial to update to Switchvox…
#Cve20269586 #Sangoma #Switchvox #SqlInjection #UnauthenticatedVulnerability
-
WordPress Plugin Flaw Enables Takeover Attacks on Millions of Sites
Millions of WordPress sites are at risk of takeover due to a high-severity vulnerability in the popular All-in-One WP Migration and Backup plugin, with 3.25 million sites still running a vulnerable version. This flaw, tracked as CVE-2026-19949, allows attackers to execute remote code and take full control of…
#Wordpress #Cve202619949 #AllinoneWpMigrationAndBackup #SqlInjection #RemoteCodeExecution
-
Attackers Exploit Switchvox Flaw to Deploy Reverse Shells
A critical flaw in Sangoma Switchvox SMB Edition 8.3 can let attackers execute malicious code without credentials, giving them alarming control over your system. This unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, is a serious threat that demands immediate attention.
#SqlInjection #SupplyChain #EmergingThreats #Cve20269586 #Switchvox
-
CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.
#Sangoma #Switchvox #CVE20269586 #RCE #SQLInjection #VoIP #InfoSec #ExploitedInTheWild
-
ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
-
An Apache InLong SQL injection flaw, CVE-2026-63038, lets attackers inject SQL via multiple parameters. Two more bugs join it. Upgrade to 2.4.0.
-
🔍 Testing SQL Injection Security with ANDRAX
ANDRAX brings powerful security assessment tools directly to Android. In this Reel, I test my own website to demonstrate how an SQL Injection vulnerability can be identified and why proper web security matters.
💬 Comment "ANDRAX" and I'll share more cybersecurity resources.
-
Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java…
#SqlInjection #Oracle #Java #WindowsPrivilegeEscalation #SupplyChainAttack
-
How Bad Was The PeerTube Exploit?
-
If you're looking at the #Wordpress PoC for https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q at https://github.com/attackercan/wp2shell-poc2 , please be aware that the "check" and "read" PoC do not always work. I assume it was created on an empty Wordpress install (with 0 posts). But if it's populated, the OR SLEEP(3) is short circuited away. Trust your version.php instead.
(wp2shell-poc does not have an issue tracker enabled to report this to.)
-
🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).
- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryRunning WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.
ℹ️ Additional information on ZEN SecDB
https://secdb.nttzen.cloud/updates/a5a57351-ee12-401e-89a9-eca20d3ba7af/wp2shell-vulnerability#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence -
🕸️ Hoy Miércoles 15 de Julio a las 8:00 pm (UTC -05:00) iniciamos el Curso de Hacking Aplicaciones Web 2026 🕷️ 🚀 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 🎯 De 8:00 pm a 11:00 pm (UTC -05:00) 👁🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #AppSec #OWASP #SQLInjection #XSS #SSRF #RCE #BrokenAccessControl -
CVE-2026-1207 is a Django SQL injection flaw (CVSS 8.3) in PostGIS raster lookups. Canada's CCCS says it is exploited in the wild. Patch now.
-
A look at CVE-2020-24932, the critical SQL injection in Complaint Management System v1.0 that allowed full database disclosure through a single parameter. https://hackernoon.com/anatomy-of-a-critical-sql-injection-lessons-from-cve-2020-24932 #sqlinjection
-
#Roundcube-Webmail-Instanzen mit Schadcode attackierbar | Security https://www.heise.de/news/Roundcube-Webmail-Instanzen-mit-Schadcode-attackierbar-11307545.html #Patchday #SQLinjection #XSS #CrossSiteScripting
-
Jetzt patchen! Angreifer nutzen kritische Schadcode-Lücke in #Drupal aus | Security https://www.heise.de/news/Jetzt-patchen-Angreifer-nutzen-kritische-Schadcode-Luecke-in-Drupal-aus-11305870.html #Patchday #exploit #SQLinjection #PostgreSQL #CMS #ContentManagementSystem
-
Drupal Sites Targeted in SQL Injection Attacks
Drupal sites are under attack as SQL injection exploits are now being detected in the wild, taking advantage of a vulnerability that can be triggered without authentication. This critical flaw, CVE-2026-9082, allows attackers to execute arbitrary SQL and potentially run remote code, putting sites that use PostgreSQL at risk.
#SqlInjection #Drupal #Cve20269082 #EmergingThreats #ArbitraryCodeExecution
-
Patch immediately before public exploits emerge.
https://www.drupal.org/sa-core-2026-004
Affected:
- 8.9.0 , < 10.4.10
- 10.5.0 , < 10.5.10
- 10.6.0 , < 10.6.9
- 11.0.0 , < 11.1.10
- 11.2.0 , < 11.2.12
- 11.3.0 , < 11.3.10CVE-2026-9082 - Highly critical - SQL Injection
CVE-2026-8495 - Missing Authorization
CVE-2026-8493 - XSS
CVE-2026-8492
CVE-2026-8491#Drupal #PHP #CyberSecurity #Infosec #CVE #WebSecurity #PostgreSQL #SqlInjection #PrivilegeEscalation #XSS
-
#PostgreSQL: Updates stopfen hochriskante Sicherheitslecks | Security https://www.heise.de/news/PostgreSQL-Updates-stopfen-hochriskante-Sicherheitslecks-11297485.html #SQL #Patchday #SQLinjection
-
🚨 CRITICAL: CVE-2026-46364 in phpMyFAQ <4.1.2 allows unauthenticated SQL injection via /api/captcha. Attackers can exfiltrate user creds, admin tokens, and SMTP info. Restrict endpoint & use WAF until patch is confirmed. https://radar.offseq.com/threat/cve-2026-46364-improper-neutralization-of-special--9adafcbf #OffSeq #SQLInjection #Infosec
-
#SAP-#Patchday: Kritische Sicherheitslücken erlauben unbefugte Anmeldung | Security https://www.heise.de/news/SAP-Patchday-Kritische-Sicherheitsluecken-erlauben-unbefugte-Anmeldung-11291173.html #SQLinjection
-
🚨 CRITICAL: SQL injection (CVE-2026-34260, CVSS 9.6) in SAP S/4HANA (SAP_BASIS 751-816). Authenticated attackers can access sensitive data & crash apps. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-34260-cwe-89-improper-neutralization-of-s-4864cd58 #OffSeq #SAP #Infosec #SQLInjection
-
Oh, another groundbreaking article promising to unravel Intel's secret #voodoo memory #tech, only to be thwarted by the mighty #Cloudflare shield. 🤦♂️ Because who needs cutting-edge insights when you can play "Guess the SQL Injection"? 🚀💻
https://www.hpcwire.com/2026/02/05/what-is-z-angle-memory-and-why-is-intel-developing-it/ #Intel #SQLInjection #TechNews #HackerNews #ngated