隠者 Inja Security
隠者 Inja Security
  • Home
  • ~$ whoami

April 2024

Application Security

CVE-2024-29320: SQL Injection in Wallos

Introduction An open-source personal subscription tracker, Wallos designed to empower people to manage their finances with ease. Wallos is written in PHP with a SQLite database, it has over 1.000 stars in GitHub and over 100.00 downloads for its Docker image. A quick search on Shodan reveals at least 66 Read more…

By Matheus Boschetti, 1 yearApril 4, 2024 ago

Recent Posts

  • CVE-2024-29320: SQL Injection in Wallos
  • CVE-2024-27613: Arbitrary File Manipulation in Numbas
  • Bypassing PowerShell CLM with Custom Runspaces
  • Striking Blue: Picking Digital Lockers
  • Leveraging Process Injection for AV Evasion

Archive

  • April 2024
  • March 2024
  • August 2023
  • July 2023
  • June 2023
  • January 2023
  • October 2022
  • July 2022
  • April 2022
  • February 2022

Categories

  • Application Security
  • Binary Exploitation
  • Certification Review
  • Defense Evasion
  • Malware Development
  • Open Source Software (OSS)
  • Phishing
  • Red Team
  • Security Research
  • ~$ whoami
Hestia | Developed by ThemeIsle