Tag
Detection of Potential HTTP Downgrade Attacks
1 rule 1 TTPAttackers may force HTTP protocol downgrades from secure versions like HTTP/2 to legacy versions to exploit header parsing inconsistencies and facilitate request smuggling or cache poisoning.
Critical RCE Vulnerability in Apache Struts (S2-067)
1 rule 2 TTPs 1 CVEA critical remote code execution vulnerability (CVE-2024-53677) in Apache Struts versions 2.0.0 through 6.3.0.2 allows attackers to leverage path traversal during file uploads to execute arbitrary code.
Privilege Escalation in YITH WooCommerce Waitlist Premium Plugin
1 rule 1 TTP 1 CVEAuthenticated attackers can exploit a missing capability check and nonce validation in the YITH WooCommerce Waitlist Premium plugin to elevate privileges to administrator.
Authentication Bypass in Support Genix WordPress Plugin
2 TTPs 1 CVEThe Support Genix WordPress plugin is vulnerable to authentication bypass and administrator account takeover due to a weak cryptographic implementation in the guest ticket login feature.
SQL Injection Vulnerability in SourceCodester Simple Student Information System
1 rule 1 TTP 1 CVEAn unauthenticated remote SQL injection vulnerability in SourceCodester Simple Student Information System allows attackers to execute arbitrary database commands via the 'ID' parameter in 'view_department.php'.