More than 100,000 websites online run on top of
An anonymous hacker disclosed technical details and proof-of-concept exploit code for a critical zero-day remote code execution flaw in
The vulnerability could be exploited remotely by an unauthenticated attacker. The PoC exploit published by the hacker works on
The zero-day flaw in the forum software resides in the way an internal widget file of the forum software package accepts configurations via the URL parameters. The expert discovered that the package fails to validate the parameters, an attacker could exploit it to inject commands and remotely execute code on the vulnerable install.
Let’s hope that the maintainers of the
|[adrotate banner=”9″]||[adrotate banner=”12″]|