SEKurity GmbH Logo

#SQL Injection

2 Artikel markiert

[*] Filtere Artikel nach Schlagwort: SQL Injection
[+] Passende Einträge: 2
root@sekurity:~# ls -la /tags/sql-injection/* _

CVE-Forschung
sekurity-team

InSEKurity of the Week (CW30/2026): WordPress Core wp2shell Pre-Auth RCE (CVE-2026-63030 & CVE-2026-60137)

Eine Route-Confusion im REST-API-Batch-Endpunkt von WordPress Core, verkettet mit einer SQL-Injection in WP_Query, ermoeglicht unauthentifizierten Angreifern Remote Code Execution auf einer Standard-WordPress-Installation -- ohne Plugins, ohne Zugangsdaten, und sie wird bereits aktiv ausgenutzt.

01
CVE-Forschung
sekurity-team

InSEKurity der Woche (KW21/2026): Drupal Core Anonyme SQL Injection (CVE-2026-9082)

Eine unauthentifizierte SQL Injection im PostgreSQL EntityQuery-Handler von Drupal Core -- anonyme Angreifer verwandeln JSON-Objekt-Schluessel und JSON:API-Filterparameter in rohe SQL-Fragmente. Von Drupal mit 23/25 'Highly Critical' bewertet, CISA KEV, 15.000+ Exploit-Versuche in 48 Stunden

02

root@sekurity:~# echo "Ende der Ergebnisse für Schlagwort: SQL Injection"
Ende der Ergebnisse für Schlagwort: SQL Injection
root@sekurity:~# _