본문 바로가기

php

rConfig에서 치명적인 RCE 취약점 발견돼 Watch Out IT Admins! Two Unpatched Critical RCE Flaws Disclosed in rConfig 한 사이버 보안 연구원이 rConfig 유틸리티에서 패치되지 않은 치명적인 원격 코드 실행 취약점 두 개에 대한 세부 정보와 PoC 익스플로잇을 공개했습니다. 이 중 최소 하나는 인증되지 않은 원격 공격자들이 타깃 서버와 연결된 네트워크 기기를 해킹하도록 허용합니다. native PHP로 작성된 rConfig는 무료 오픈소스 네트워크 기기 구성 관리 유틸리티로 네트워크 엔지니어가 네트워크 기기를 구성하고 주기적으로 구성 스냅샷을 찍는 데 사용할 수 있습니다. rConfig의 웹사이트에 따르면, 이는 스위치, 라우터, 방화벽, 로드 밸런서, WAN 옵티마이저를 포함한 네트워.. 더보기
Watch Out IT Admins! Two Unpatched Critical RCE Flaws Disclosed in rConfig If you're using the popular rConfig network configuration management utility to protect and manage your network devices, here we have an important and urgent warning for you. A cybersecurity researcher has recently published details and proof-of-concept exploits for two unpatched, critical remote code execution vulnerabilities in the rConfig utility, at least one of which could allow unauthentic.. 더보기
New PHP Flaw Could Let Attackers Hack Sites Running On Nginx Servers Source for https://thehackernews.com/2019/10/nginx-php-fpm-hacking.html New PHP Flaw Could Let Attackers Hack Sites Running On Nginx Servers A new security vulnerability in php-fpm could allow attackers to hack PHP websites running on Nginx servers. thehackernews.com If you're running any PHP based website on NGINX server and have PHP-FPM feature enabled for better performance, then beware of a .. 더보기
Warning: Researcher Drops phpMyAdmin Zero-Day Affecting All Versions September 18, 2019Wang Wei A cybersecurity researcher recently published details and proof-of-concept for an unpatched zero-day vulnerability in phpMyAdmin—one of the most popular applications for managing the MySQL and MariaDB databases. phpMyAdmin is a free and open source administration tool for MySQL and MariaDB that's widely used to manage the database for websites created with WordPress,.. 더보기
Multiple Code Execution Flaws Found In PHP Programming Language Multiple Code Execution Flaws Found In PHP Programming Language September 06, 2019Wang Wei Maintainers of the PHP programming language recently released the latest versions of PHP to patch multiple high-severity vulnerabilities in its core and bundled libraries, the most severe of which could allow remote attackers to execute arbitrary code and compromise targeted servers. Hypertext Preprocess.. 더보기