The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Public source code repositories, from Sourceforge to GitHub , from the Linux Kernel Archives to ReactOS.org , from PHP Packagist to the Python Package Index , …
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service or incorrect …
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service or incorrect v…
Ethical hacking is a proactive approach using the same techniques like the same programming languages as malicious hacking. Ethical hackers must stay current o…
XSS in phoromatic_r_add_test_details.php (CVE-2022-40704) References: - https://bugs.mageia.org/show_bug.cgi?id=31423 - https://lists.fedoraproject.org/archive…
It was discovered that there was a potential cross-site scripting vulnerability in smarty3, a widely-used PHP templating engine. For Debian 10 buster, this pro…
Multiple security issues were discovered in PHP, a widely-used open source general purpose scripting language which could result in denial of service, informat…
The NixOS 22.11 release also comes with OpenSSL 3, OpenSSH 9.1, PHP 8.1, Perl 5.36, and Python 3.10 by default, support for Linode cloud images, native compila…
Multiple security issues were discovered in PHP, a widely-used open source general purpose scripting language which could result an denial of service, informat…
It was discovered that there was a potential arbitrary file read vulnerability in twig, a PHP templating library. It was caused by insufficient validation of t…
Charles Fol discovered two security issues in PHP, a widely-used open source general purpose scripting language which could result an denial of service or pote…
Smarty3 is a template engine for PHP. It was found that template authors could inject PHP code by choosing a malicious {block} name or {include} file name. For…
Several security vulnerabilities have been discovered in smarty3, the compiling PHP template engine. Template authors are able to run restricted static php met…
Update to 21.08.8 to fix CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502. https://www.schedmd.com/news.php?id=260#OPT_260
Update to 21.08.8 to fix CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502. https://www.schedmd.com/news.php?id=260#OPT_260
Update to 21.08.8 to fix CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502. https://www.schedmd.com/news.php?id=260#OPT_260
Smarty3, a template engine for PHP, allowed template authors to run restricted static php methods. The same authors could also run arbitrary PHP code by crafti…
Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how…
Two security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure or denial of s…
Thomas Chauchefoin from SonarSource discovered that in Zabbix, a server/client network monitoring system, after the initial setup process, some steps of setup.…
It was found that in libphp-adodb, a PHP database abstraction layer library, an attacker can inject values into the PostgreSQL connection string by bypassing a…
CloudLinux's security platform for Linux-based websites and web servers contains a high-severity PHP deserialization bug, leaving web servers vulnerable to cod…
An out-of-bounds read and write flaw was discovered in the PHP-FPM code, which could result in escalation of privileges from local unprivileged user to the roo…
An out-of-bounds read and write flaw was discovered in the PHP-FPM code, which could result in escalation of privileges from local unprivileged user to the roo…