Directory Traversal

Contrast Security discovers Netflix OSS Genie application path traversal vulnerability that can lead to RCE during file upload
Genie is a federated big data orchestration and execution engine developed and open sourced by Netflix. ...

Drupal Patches Highly Critical Remote Code Execution Vulnerability
Websites based on the Drupal content management system might be affected by a highly critical vulnerability that could result in remote code execution. The vulnerability affects websites running Drupal 8 with RESTful ...

WordPress Sites Hacked Through Vulnerable Payment Forms Plug-in
Hackers are exploiting vulnerabilities in a WordPress plug-in that was patched months ago without being publicly announced. A different vulnerability has been found in the same plug-in during a recent forensic investigation ...

Zip Slip Vulnerability Affecting Thousands of Apps Puts Systems at Risk
Thousands of software projects and libraries contain code that extracts archives in an insecure way, allowing attackers to write arbitrary files outside the intended directories. In many cases, this can lead to ...