Aggregator
Submit #512330: www.zzskzy.com Refined warehousing management system v1.3 RCE [Accepted]
Apache Camel Vulnerability Allows Attackers to Inject Arbitrary Headers
A newly disclosed security vulnerability in Apache Camel, tracked as CVE-2025-27636, has raised alarms across the cybersecurity community. The flaw allows attackers to inject arbitrary headers into Camel Exec component configurations, potentially enabling remote code execution (RCE). The vulnerability impacts several versions, including 3.10.0 through 3.22.3, 4.8.0 through 4.8.4, and 4.10.0 through 4.10.1. This exploit highlights the dangers of […]
The post Apache Camel Vulnerability Allows Attackers to Inject Arbitrary Headers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-51319 | Zucchetti Ad Hoc Infinity up to 2.4 /jsp/zimg_upload.jsp file inclusion
CVE-2025-2214 | Microweber 2.0.19 Settings index.php group cross site scripting
Submit #512316: https://github.com/Doufox/doufox doufoxcms 0.2.0 Directory traversal and arbitrary file modifications [Accepted]
BSides Exeter 2024 – Purple Track – Cedar, An Open Source Project To Help You Decouple Your Authorisation Logic
Author/Presenter: Ricardo Sueiras
Our thanks to Bsides Exeter, and the Presenters/Authors for publishing their timely Bsides Exeter Conference content. All brought to you via the organizations YouTube channel.
The post BSides Exeter 2024 – Purple Track – Cedar, An Open Source Project To Help You Decouple Your Authorisation Logic appeared first on Security Boulevard.