A security flaw has been found in the web installer for ClipBucket V5, a website content management tool some hosting clients may use. The installer does not properly check or filter a specific input setting (called php_cli_filepath) before using it to run system commands on the server.This flaw does not require attackers to have login access to ...
Continue reading
A security flaw has been identified in the Total Donations plugin for WordPress, a tool many website owners use to add and manage donation features on their sites. All versions of this plugin up to and including version 2.0.5 are affected by this vulnerability.
This issue allows unauthenticated attackers, meaning people who do not have any login ...
Continue reading
Oracle has identified an access control flaw in its Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, two tools commonly used to manage website traffic and connect web applications to backend systems. The flaw means these tools do not properly restrict who can interact with the data and settings they manage.If this vulnerability is ...
Continue reading
A security flaw has been identified in Gitea, a popular tool for hosting and managing code repositories that many of our clients use for development and website-related projects. This is a code injection vulnerability, which allows unauthorized code to be run on the platform without proper permission.To exploit this flaw, an attacker needs to ...
Continue reading