MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As ...
Continue reading
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the ...
Continue reading
A security vulnerability has been identified in specific versions of PHP, the programming language that powers most dynamic, interactive websites. The flaw exists in the bccomp() function, a tool used to compare very large numbers. If this function processes input submitted directly by website visitors (rather than pre-vetted, trusted data), ...
Continue reading
A security flaw has been identified in specific versions of PHP, the software that powers many dynamic websites. The issue occurs when backslashes in input provided by visitors to your site (such as form submissions or URL parameters) are not handled correctly. This creates a simple path for attackers to carry out SQL injection, a type of attack ...
Continue reading