Intelligence Reporting

typo3 (1)

PHP Code Execution Attack A new exploitation technique has been discovered that allow attackers to trigger critical deserialization vulnerabilities in PHP programming language using previously low-risk considered functions. The new technique leaves web applications open to remote code execution attacks, including websites powered by some popular content management systems like WordPress and Typo3. PHP unserialization was first discovered in 2009 which allows attackers to perform various attacks…