CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jul 15, 2026

Quotes Llama WordPress Plugin SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the Quotes Llama WordPress plugin, affecting versions prior to 3.1.6. The issue arises because the plugin fails to properly sanitize and escape user-supplied parameters before incorporating them into SQL queries. This flaw allows unauthenticated attackers to execute UNION-based SQL injection attacks, potentially leading to the extraction of arbitrary data from the database, including password hashes.

5.7
Jul 15, 2026

Shibboleth WordPress Plugin Authentication Bypass Vulnerability Allowing Unauthenticated Administrator Account Creation

A vulnerability in the Shibboleth WordPress plugin, affecting versions prior to 2.5.4, allows for unauthenticated administrator account creation through identity header spoofing. When the HTTP header identity mode is enabled without an anti-spoofing key, the plugin fails to properly verify identity headers, treating them as authenticated sessions. This issue can be exploited by an unauthenticated attacker on deployments that do not strip untrusted client headers before they reach the application. The exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, and automatic account creation enabled, with the default administrator role mapping.

5.5
Jul 15, 2026

Kali Forms WordPress Plugin Post Duplication Vulnerability Allowing Arbitrary Private Metadata Disclosure

A vulnerability exists in the Kali Forms WordPress plugin, specifically in versions prior to 2.4.17. The issue arises because the plugin's post-duplication AJAX action fails to implement a per-object capability check. This flaw enables users with Contributor-level access or higher to duplicate any post, regardless of the owner's identity, post type, or status, into a published post they control. Additionally, this vulnerability allows access to private post metadata, including sensitive information stored by other plugins.

5.4
Jul 15, 2026

Kali Forms WordPress Plugin Unauthenticated File Upload Vulnerability

A vulnerability exists in the Kali Forms WordPress plugin, specifically in versions prior to 2.4.17. The issue arises because the plugin does not properly verify file uploads against existing forms with file-upload fields. This oversight allows unauthenticated users to upload files to the WordPress Media Library. While the uploads are restricted to WordPress's default-allowed MIME types, preventing code execution, the lack of validation poses a significant risk by enabling unauthorized file uploads.

6.5
Jul 15, 2026

ASUS Aura Wallpaper Service Improper Communication Channel Restriction Vulnerability

A vulnerability in the Aura Wallpaper Service allows local users to bypass path restrictions and perform unauthorized file operations by sending commands with arbitrary file paths. On certain models, this could also disable a specific feature. The issue affects versions through 2.1.15.0.

2.1
Jul 15, 2026

ASUS GameSDK Permissive Cross-Domain Security Policy Vulnerability Allowing NTLM Hash Theft

A vulnerability in ASUS GameSDK, present in versions through 1.0.5, allows remote users to steal local users' NTLM hashes. This is achieved by persuading users to visit a malicious webpage that triggers a request containing a UNC path to the application's local service endpoint. The vulnerability could lead to unauthorized information disclosure, data tampering, and potential disruption of the GameSDK application, as well as unauthorized access to the victim's information on other services.

2.9
Jul 15, 2026

ASUS System Control Interface and ASUS Business Manager Out-of-Bounds Read Vulnerability

A vulnerability allowing out-of-bounds read has been identified in ASUS System Control Interface version 3 prior to 3.1.66.0, ASUS System Control Interface earlier than version 1.1.40.0, and ASUS Business Manager prior to version 3.0.38.0. This vulnerability allows a local administrator to read memory regions beyond the intended firmware boundary by sending a crafted IOCTL request that bypasses validation.

4.9
Jul 15, 2026

ASUS System Control Interface Untrusted Pointer Dereference Vulnerability Allowing Arbitrary Memory Operations

A vulnerability exists in ASUS System Control Interface versions 3.1.59.0 (x64) and earlier, as well as in ASUS Business Manager versions prior to 3.0.38.0. This vulnerability allows local administrators to perform arbitrary read and write operations on physical memory. The issue arises from an untrusted pointer dereference in the ASUS System Control Interface, which enables the manipulation of memory through crafted IOCTL requests to the driver, bypassing operating system memory protections.

4.9
Jul 15, 2026

ASUS System Control Interface and ASUS Business Manager Sensitive Information Disclosure Vulnerability

A vulnerability exists in the ASUS System Control Interface driver and ASUS Business Manager, allowing local administrators to disclose sensitive information through crafted IOCTL requests. This issue arises from the allocation of resources without proper limits and throttling, coupled with sensitive information not being removed before reuse. In severe cases, this vulnerability may lead to a denial-of-service condition on the system.

4.9
Jul 15, 2026

ASUS Routers Improper Certificate Validation and Integrity Check Vulnerability Allowing Remote Command Execution

A vulnerability in certain ASUS router models, related to improper validation of integrity check values and certificates, enables a remote man-in-the-middle (MITM) attacker to make the router download and execute arbitrary commands from a spoofed server. This issue affects ASUS routers running firmware versions 3.0.0.4_386 series, 3.0.0.4_388 series, and 3.0.0.6_102 series.

3.0
Jul 15, 2026

ASUS Routers SQL Injection Vulnerability in Web Management Interface

A SQL injection vulnerability has been identified in the web management interface of certain ASUS router models. This issue allows remote authenticated users to bypass existing input validation and disclose confidential information by sending crafted requests. The vulnerability arises from improper neutralization of special elements used in SQL commands.

2.6
Jul 15, 2026

TP-Link Kasa EC70 and EC71 Static Cryptographic Key Information Disclosure Vulnerability

A vulnerability exists in the Kasa EC70 v4 and EC71 v4 firmware due to a hardcoded cryptographic private key stored in a read-only filesystem, shared across devices. An attacker with access to the firmware image can extract this key. Exploitation may allow an unauthenticated attacker on the same network to use the key in the web management service, compromising the confidentiality of encrypted communications. This could lead to passive decryption of traffic or active man-in-the-middle attacks.

2.5
Jul 15, 2026

TP-Link Kasa EC70 and EC71 Information Disclosure Vulnerability

A vulnerability allowing information disclosure has been identified in the TP-Link Kasa EC70 v4 and EC71 v4 models. This issue arises in the local discovery mechanism, which exposes sensitive geolocation data without requiring authentication. An attacker on the same local network can exploit this vulnerability by sending crafted responses to retrieve geolocation-related information. The vulnerability impacts confidentiality by exposing sensitive location data, with no known effects on integrity or availability.

2.5
Jul 14, 2026

Ciena Products Authentication Bypass Vulnerability

An authentication bypass vulnerability has been identified in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. This vulnerability arises from improper handling of HTTP request paths and headers, enabling an unauthenticated attacker to manipulate requests and bypass authentication, along with associated audit logging controls.

3.5
Jul 14, 2026

Ciena Navigator NCS and MCP Default Password Vulnerability in Hidden System Accounts

A vulnerability exists in Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP) due to hidden system accounts used for internal operations. Some of these accounts have default passwords that could be easily guessed. Although these accounts have limited permissions individually, an attacker might exploit them in conjunction with other vulnerabilities to launch a more significant attack, potentially leading to unauthorized privilege escalation.

2.5
Jul 14, 2026

OpenHTJ2K Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in OpenHTJ2K versions through 0.18.4. This vulnerability allows an attacker to execute arbitrary code by exploiting the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded functions in source/core/interface/decoder.cpp. The issue arises from unchecked tile indices in the J2K tile dispatch process, leading to out-of-bounds memory access and information leaks.

3.7
Jul 14, 2026

OpenHTJ2K Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

A buffer overflow vulnerability has been identified in OpenHTJ2K versions through 0.18.4. This vulnerability allows an attacker to execute arbitrary code by exploiting the j2k_precinct_subband::parse_packet_header() function in the coding_units.cpp file.

4.4
Jul 14, 2026

CAXperts Universal Plant Viewer WebServices Server Broken Access Control Vulnerability Allowing Denial-of-Service

A broken access control vulnerability has been identified in CAXperts Universal Plant Viewer WebServices Server version 2.7.6. This vulnerability allows authenticated attackers with low-level privileges to cause a denial-of-service by deactivating the application license on the web server. The issue arises because the '/api/License/deactivateOffline' endpoint lacks proper authorization checks, enabling unauthorized license deactivation.

4.0
Jul 14, 2026

zhinianboke xianyu-auto-reply HTTP Permission Trust Vulnerability in Payment Withdrawal Review Endpoint

A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend Web API service. The issue arises in the payment withdrawal review endpoint, which is part of the application's financial transaction management. This vulnerability allows for unauthorized manipulation of withdrawal review actions, potentially leading to improper approval of withdrawal requests. The flaw can be exploited remotely, creating a risk of financial misconduct within the application.

4.8
Jul 14, 2026

zhinianboke xianyu-auto-reply Unauthenticated User Privilege Escalation Vulnerability

A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend user endpoint of the API. This vulnerability allows for unauthorized actions such as modifying user roles and statuses, bypassing CAPTCHA requirements, and manipulating withdrawal approval processes. The issue arises from several API endpoints that lack proper authentication and authorization checks, particularly those related to user management and financial transactions.

4.8
Jul 14, 2026

Mastergo-Design Mastergo-Magic-MCP Path Traversal Vulnerability in Component Workflow Tool

A path traversal vulnerability has been identified in the Mastergo-Design Mastergo-Magic-MCP tool, specifically in versions up to 0.2.0. The issue arises within the 'mcp__getComponentGenerator' function, where the 'rootPath' argument is not properly validated. This flaw allows for the creation of directories and files in an attacker-specified location under the '.mastergo/' directory. The vulnerability requires local exploitation, and although it has been publicly disclosed, the project maintainers have not yet addressed it.

3.3
Jul 14, 2026

Matter SDK Reachable Assertion Vulnerability in Command Processing Logic

A reachable assertion vulnerability has been identified in the Matter SDK (connectedhomeip) versions prior to 1.4.0. The issue arises in the interaction model command processing logic, where an InvokeCommandRequest sent to a nonexistent endpoint and cluster is incorrectly validated. This flaw, due to missing checks, leads to a VerifyOrDie failure in ProcessCommandDataIB, causing a crash (SIGABRT). The vulnerability has been acknowledged and fixed in a later revision (PR #37207).

5.4
Jul 14, 2026

Matter SDK Use of Uninitialized Value Vulnerability Leading to Denial-of-Service

A vulnerability exists in the Matter SDK (connectedhomeip) prior to version 1.4.0, where the 'GetDestinationGroupId().Value()' method is invoked without verifying if a value is present. This oversight causes a crash when an 'InvokeCommand' is sent without initializing the destination group ID. The vulnerability affects all versions before the patch in commit 0360cc3 (Dec 5, 2024) and results in a denial-of-service condition by causing a SIGABRT crash.

5.4
Jul 14, 2026

Matter SDK Null Pointer Dereference Vulnerability in ReadRevisionAttribute Function

A null pointer dereference vulnerability has been identified in the Matter SDK (connectedhomeip) versions prior to 1.4.0. The issue affects the ReadRevisionAttribute function, which is used in several clusters, including Channel, Account Login, TargetNavigator, ContentLauncher, and MediaPlayback. The vulnerability arises because the function does not properly validate the delegate pointer before dereferencing it, allowing remote unauthenticated attackers to send crafted read requests that cause the device to crash, leading to a denial-of-service condition.

5.4
Jul 14, 2026

Matter SDK Reachable Assertion Vulnerability in Level Control Cluster

A reachable assertion vulnerability in the Matter SDK (connectedhomeip) has been identified, affecting versions prior to 1.4.2. The issue arises within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is issued and immediately followed by a write of OperationMode=2 in the Pump Configuration and Control cluster, the server tick function violates the assertion 'currentLevel < maxLevel', leading to a crash. This vulnerability can be exploited remotely without authentication, causing a denial-of-service condition.

4.6
Jul 14, 2026

Rclone Authorization Bypass Vulnerability in Restic Server Allowing Cross-User Repository Access

An authorization bypass vulnerability has been identified in Rclone's Restic server implementation, specifically in versions prior to 1.74.4. The issue arises when the '--private-repos' option is enabled, allowing authenticated users to manipulate URL paths to access, overwrite, or delete files in other users' private repositories. This vulnerability exploits the fact that the authorization check relies on a routed user path segment, while the backend object key is created from the raw, uncleaned URL path. As a result, an authenticated user can craft a request that appears to be authorized but actually targets a different user's repository. The impact of this vulnerability is significant, as it allows for unauthorized access to sensitive repository metadata and objects, potentially leading to data corruption or loss.

5.4
Jul 14, 2026

Rclone Path Traversal Vulnerability in Archive Extraction

A path traversal vulnerability has been identified in Rclone's archive extraction feature, prior to version 1.74.4. The issue allows crafted archive entries to escape the designated extraction prefix, potentially overwriting or creating files in the same bucket or path scope on the destination remote. This vulnerability arises because the extraction process does not properly validate archive entry names, allowing parent path components to be exploited.

5.7
Jul 14, 2026

jadx Zip Path Traversal Vulnerability Leading to Arbitrary File Overwrite and Remote Code Execution

A vulnerability in jadx versions 1.5.2 through 1.5.5 allows a malicious .xapk file to cause arbitrary file overwriting. This occurs because the XApkLoader resolves ZIP entry names directly to the temporary directory after a security check, potentially leading to exploitation. When jadx is launched from a directory that is an ancestor of the config directory, this vulnerability can be exploited to execute arbitrary code by planting a JAR file in the plugins/dropins directory, which is loaded as a plugin on the next run of jadx.

5.3
Jul 14, 2026

Rclone Symlink Handling Vulnerability Allows Arbitrary File Write

A vulnerability in Rclone prior to version 1.74.4 allows for arbitrary file writes through unvalidated symlink targets when using the '--links' option. Rclone recreates symlinks as '.rclonelink' text objects and writes them to local destinations without validating the target. This flaw enables an attacker to plant a symlink pointing outside the intended directory, which can then be exploited to overwrite sensitive files, such as SSH keys or shell configuration files, leading to potential code execution.

5.7
Jul 14, 2026

Pi-hole Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been identified in Pi-hole versions 6.0 through 6.4.2. The issue allows a user with code execution as the unprivileged 'pihole' user to escalate privileges to root. This is achieved by replacing the logrotate configuration file in an attacker-writable directory. The replacement file is then owned by root after being processed by a startup script, and subsequently executed as root by a scheduled cron job, leading to unauthorized actions being performed with elevated privileges.

5.7
Jul 14, 2026

Twig Template Language Sandbox Bypass Vulnerability Allowing Security Policy Mismanagement

A vulnerability exists in Twig, a template language for PHP, prior to version 3.27.0, allowing a bypass of the sandbox security policy. The issue arises because the security allow-list for filters, tags, and functions is determined when a template is first loaded and can be cached. This cached information may not reflect subsequent changes in the sandbox state, leading to a situation where a template can be reused in a sandboxed context without the appropriate security checks. The vulnerability is particularly concerning in environments that share a single Twig environment between different requests, such as with PHP-FPM or certain message queue consumers.

3.9
Jul 14, 2026

Twig Sandbox Policy Bypass Vulnerability in Column Filter

A vulnerability in Twig's column filter allows template authors to bypass sandbox restrictions and access disallowed public or magic properties. This issue affects Twig versions prior to 3.27.0 and arises when sandboxing is managed through the SourcePolicyInterface. The vulnerability exists because the column filter does not properly forward the current source to the sandbox extension, leading to a loss of policy enforcement. As a result, unauthorized property access is possible, creating a significant security risk.

4.4
Jul 14, 2026

Twig Sandbox Policy Bypass Vulnerability Allowing Unauthorized String Coercion

A vulnerability in Twig, a PHP template language, prior to version 3.27.0, allows for unauthorized coercion of Stringable objects to strings within the sandbox environment. This issue arises because the sandbox's __toString() checks do not adequately cover Traversable values used in join and replace filters, or in conjunction with the in and not in operators. As a result, Stringable objects can be converted to strings without adhering to the established sandbox policy, potentially leading to unintended consequences.

3.4
Jul 14, 2026

Twig Sandbox Policy Bypass Vulnerability via Dynamic Mapping Keys

A sandbox policy bypass vulnerability has been identified in Twig versions prior to 3.27.0. The issue arises in the ArrayExpression component, which fails to properly guard dynamic mapping keys that are converted to strings. This oversight allows PHP to directly invoke the __toString() method on Stringable objects used as mapping keys, bypassing the necessary sandbox checks. The vulnerability can be exploited by using a dynamic key expression that resolves to a Stringable object, such as a context variable, in an array mapping. This exploitation triggers the __toString() call without proper authorization, leading to a potential unauthorized disclosure of sensitive data.

4.0
Jul 14, 2026

Twig Sandbox Bypass Vulnerability in Deprecated Internal Wrappers

A vulnerability allowing sandbox bypass has been identified in Twig versions prior to 3.27.0. The issue arises in deprecated internal wrappers that do not properly forward the current sandbox state, allowing certain legacy calls to bypass sandbox restrictions. This vulnerability affects applications that use the deprecated 'twig_array_some()', 'twig_array_every()', and 'twig_check_arrow_in_sandbox()' functions within a sandboxed environment.

4.4
Jul 14, 2026

Adobe Content Credentials Uncontrolled Resource Consumption Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in the Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability allows an attacker to exhaust system resources, causing an application denial-of-service condition. Exploitation does not require user interaction.

2.0
Jul 14, 2026

Adobe Content Credentials Integer Overflow Vulnerability Leading to Application Denial-of-Service

An integer overflow vulnerability has been identified in Adobe Content Credentials, specifically in the Content Credentials Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability can be exploited to cause an application denial-of-service, where the application crashes and becomes unavailable. Notably, exploitation does not require user interaction.

2.0
Jul 14, 2026

Adobe Content Credentials Improper Input Validation Vulnerability Leading to Arbitrary File System Read

A vulnerability in Adobe Content Credentials has been identified, stemming from improper input validation. This issue could allow an attacker to read arbitrary files from the file system, accessing sensitive information and directories beyond the intended access scope. Exploitation requires user interaction, as a victim must open a malicious file. The vulnerability affects multiple components of the Content Credentials SDK, including the Rust SDK, Command-Line Tool, and JS SDK, all prior to specific updated versions.

2.3
Jul 14, 2026

Adobe Content Credentials Improper Input Validation Vulnerability Leading to Application Denial-of-Service

A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in the Content Credentials Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability arises from improper input validation, allowing an attacker to crash the application and create a denial-of-service condition. Notably, exploitation of this issue does not require user interaction.

3.4
Jul 14, 2026

Adobe Content Credentials Improper Input Validation Vulnerability Leading to Application Denial-of-Service

A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in the Content Credentials Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability arises from improper input validation, allowing an attacker to crash the application and create a denial-of-service condition. Notably, exploitation of this issue does not require user interaction.

3.0
Jul 14, 2026

Adobe Illustrator Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution

A vulnerability allowing out-of-bounds write has been identified in Adobe Illustrator. This issue could lead to arbitrary code execution within the context of the current user. The vulnerability affects Illustrator 2025 versions through 29.8.7 and Illustrator 2026 versions through 30.5, all on Windows. Exploitation requires user interaction, as a victim must open a malicious file.

5.3
Jul 14, 2026

Adobe Illustrator Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution

A vulnerability allowing out-of-bounds write has been identified in Adobe Illustrator. This issue could lead to arbitrary code execution within the context of the current user. The vulnerability affects Illustrator 2025 versions 29.8.7 and earlier, and Illustrator 2026 versions 30.5 and earlier, both on Windows. Exploitation requires user interaction, as a victim must open a malicious file.

5.3
Jul 14, 2026

Adobe Illustrator Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution

A vulnerability allowing out-of-bounds write has been identified in Adobe Illustrator. This issue could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file. The vulnerability affects Adobe Illustrator 2025 versions through 29.8.7 and Adobe Illustrator 2026 versions through 30.5, both on Windows.

5.3
Jul 14, 2026

Adobe Illustrator Improper Input Validation Vulnerability Allowing Arbitrary Code Execution

A vulnerability in Adobe Illustrator related to improper input validation has been identified, which could lead to arbitrary code execution in the context of the current user. This issue affects Illustrator 2025 versions through 29.8.7 and Illustrator 2026 versions through 30.5 on Windows. Exploitation of this vulnerability requires user interaction, as a victim must open a malicious file.

5.3
Jul 14, 2026

Adobe Content Credentials Improper Input Validation Vulnerability Allowing Security Feature Bypass

A vulnerability in CAI Content Credentials has been identified, stemming from improper input validation. This issue could lead to a security feature bypass, allowing an attacker to gain unauthorized write access. Notably, exploitation of this vulnerability does not require any user interaction. The affected products include the Content Credentials Rust SDK, Command-Line Tool, and JS SDK, all of which are vulnerable in versions prior to the latest release.

2.4
Jul 14, 2026

Adobe Content Credentials Improper Input Validation Vulnerability Leading to Application Denial-of-Service

A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in the Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability arises from improper input validation, allowing an attacker to crash the application and disrupt service. Notably, exploitation does not require user interaction.

3.0
Jul 14, 2026

Adobe Content Credentials Integer Underflow Vulnerability Leading to Application Denial-of-Service

A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in the Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability arises from an integer underflow issue that can be exploited to crash the application, causing a denial-of-service condition. Notably, exploitation of this vulnerability does not require user interaction.

2.0
Jul 14, 2026

Adobe Content Credentials Integer Underflow Vulnerability Leading to Application Denial-of-Service

A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in the Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability arises from an integer underflow issue that can be exploited to crash the application, causing a denial-of-service condition. Notably, exploitation of this vulnerability does not require user interaction.

2.0
Jul 14, 2026

Adobe Content Credentials Insufficiently Protected Credentials Vulnerability Allowing Unauthorized Read Access

A vulnerability in Adobe Content Credentials SDKs, including the Rust SDK, Command-Line Tool, and JS SDK, prior to the latest versions, allows for unauthorized read access to sensitive information. This issue arises from insufficiently protected credentials, and exploitation does not require user interaction.

3.4
Jul 14, 2026

Adobe Content Credentials Server-Side Request Forgery Vulnerability Allowing Arbitrary Code Execution

A Server-Side Request Forgery (SSRF) vulnerability has been identified in Adobe Content Credentials, specifically in the Rust SDK, Command-Line Tool, and JS SDK, all prior to the latest versions. This vulnerability could lead to arbitrary code execution in the context of the current user. An attacker might exploit this issue to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation requires user interaction, such as visiting a maliciously crafted URL or engaging with a compromised web page.

2.7