В прошлом году мы с командой мобильного приложения «Госуслуги Авто» выпустили новый сервис — оформление ДТП без участия инспектора ГИБДД. В этой статье я расскажу, как мы разрабатывали сервис, какие грабли собрали, чему научились и каких результатов достигли. Читать далее
Хабр — это крупнейшая русскоязычная площадка для IT‑специалистов, технологических стартапов и новостей сферы новых технологий. Вместе с тем, площадка не перестает развиваться, и это обосновано. Я хотел бы внести небольшие идеи и вклад в развитие Хабра,…
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.5 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this…