article thumbnail

Drupal developers fixed a code execution flaw in the popular CMS

Security Affairs

“Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012 ) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010 ).” ” reads the advisory. Follow me on Twitter: @securityaffairs and Facebook.

CMS 110
article thumbnail

EnemyBot malware adds new exploits to target CMS servers and Android devices

Security Affairs

LFI CVE-2018-16763 Fuel CMS 1.4.1 RCE CVE-2020-5902 F5 BigIP RCE No CVE (vulnerability published on 2019) ThinkPHP 5.X The post EnemyBot malware adds new exploits to target CMS servers and Android devices appeared first on Security Affairs. Follow me on Twitter: @securityaffairs and Facebook. Pierluigi Paganini.

CMS 141
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Joomla CMS Discloses Data Leak

Adam Levin

Joomla administrators announced that they had removed all accounts that had been inactive since before 2019, and enabled multi-factor authentication for users on the site. The post Joomla CMS Discloses Data Leak appeared first on Adam Levin.

CMS 58
article thumbnail

CVE-2019-6340 Critical flaw in Drupal allows Remote Code Execution

Security Affairs

Security expert found a “highly critical” vulnerability (CVE-2019-6340) in the popular Drupal CMS that could be exploited for remote code execution. Drupal released security updates that addresses a “highly critical” vulnerability in the popular Drupal CMS, tracked as CVE-2019-6340, that could be exploited for remote code execution.

CMS 82
article thumbnail

CMS targets customer satisfaction with mobile app

CGI

CMS targets customer satisfaction with mobile app. Wed, 04/10/2019 - 13:05. The Centers for Medicare & Medicaid Services (CMS) has joined the movement with “ What’s Covered ,” a new app that lets people with original Medicare plans, caregivers and others quickly see whether Medicare covers a specific medical item or service.

CMS 40
article thumbnail

KashmirBlack, a new botnet in the threat landscape that rapidly grows

Security Affairs

Security experts spotted a new botnet, tracked as KashmirBlack botnet, that likely infected hundreds of thousands of websites since November 2019. The KashmirBlack botnet has been active at least since November 2019, operators leverages dozens of known vulnerabilities in the target servers.

CMS 114
article thumbnail

CVE-2019-6342 flaw allows hackers to fully compromise Drupal 8.7.4 websites

Security Affairs

which addresses the CVE-2019-6342 flaw that allows hackers to take control of Drupal 8 sites. is affected by a critical flaw, tracked as CVE-2019-6342, that could be exploited by attackers to take control of Drupal 8 websites. Department of Homeland Security (DHS) has also published a security update for the CVE-2019-6342 flaw.

CMS 81