Aggregator
El Dorado
3 days 11 hours ago
cohenido
CVE-2017-2428 | Apple watchOS up to 3.1 HTTPProtocol cross site scripting (HT207602 / Nessus ID 99264)
3 days 11 hours ago
A vulnerability has been found in Apple watchOS up to 3.1 and classified as critical. This vulnerability affects unknown code of the component HTTPProtocol. The manipulation leads to basic cross site scripting.
This vulnerability was named CVE-2017-2428. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Black Basta operators phish employees via Microsoft Teams
3 days 12 hours ago
Black Basta ransomware affiliates are still trying to trick enterprise employees into installing remote access tool by posing as help desk workers, now also via Microsoft Teams. Phishing via MS Teams Earlier this year, Rapid7 warned about Black Basta using the following social engineering trick: they flood the target employee’s email inbox with spam – typically from automated systems or services that send confirmations or notifications – and then phone them to offer assistance, while … More →
The post Black Basta operators phish employees via Microsoft Teams appeared first on Help Net Security.
Zeljka Zorz
CVE-2003-0075 | BladeEnc 0.92.7/0.93.10/0.94.0/0.94.1/0.94.2 samplein.c myfseek integer coercion (XFDB-11227 / BID-6745)
3 days 12 hours ago
A vulnerability, which was classified as critical, was found in BladeEnc 0.92.7/0.93.10/0.94.0/0.94.1/0.94.2. This affects the function myfseek of the file samplein.c. The manipulation with the input -1 leads to integer coercion error.
This vulnerability is uniquely identified as CVE-2003-0075. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
New Type of Job Scam Targets Financially Vulnerable Populations
3 days 12 hours ago
The surge in job scams targets vulnerable individuals, mirroring pig butchering fraud tactics
IBM security advisory (AV24-616)
3 days 12 hours ago
Canadian Centre for Cyber Security
先知安全沙龙 - 北京站 11月9日开启!
3 days 12 hours ago
快来报名~
Dark Matter Announced a Harm Reduction Campaign
3 days 12 hours ago
Dark Matter Announced a Harm Reduction Campaign
Dark Web Informer
El Dorado
3 days 12 hours ago
cohenido
CVE-2008-2838 | Traindepot 0.1 index.php module path traversal (EDB-5848 / XFDB-43159)
3 days 12 hours ago
A vulnerability was found in Traindepot 0.1. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument module leads to path traversal.
This vulnerability was named CVE-2008-2838. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2839 | Traindepot 0.1 Search Module index.php query cross site scripting (EDB-5848 / XFDB-43160)
3 days 12 hours ago
A vulnerability was found in Traindepot 0.1. It has been rated as problematic. This issue affects some unknown processing of the file index.php of the component Search Module. The manipulation of the argument query leads to cross site scripting.
The identification of this vulnerability is CVE-2008-2839. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2792 | eroCMS 1.4 index.php site sql injection (EDB-5846 / XFDB-43157)
3 days 12 hours ago
A vulnerability was found in eroCMS 1.4. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument site leads to sql injection.
The identification of this vulnerability is CVE-2008-2792. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-2836 | K5n WebCalendar 1.0.4 send_reminders.php noSet code injection (EDB-5847 / XFDB-43156)
3 days 12 hours ago
A vulnerability was found in K5n WebCalendar 1.0.4 and classified as critical. Affected by this issue is some unknown functionality of the file send_reminders.php. The manipulation of the argument noSet leads to code injection.
This vulnerability is handled as CVE-2008-2836. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2008-2865 | Kalptaru Infotech PHP Site Lock 2.0 index.php articleid sql injection (EDB-5842 / XFDB-43147)
3 days 12 hours ago
A vulnerability was found in Kalptaru Infotech PHP Site Lock 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument articleid leads to sql injection.
This vulnerability is handled as CVE-2008-2865. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6738 | Mark Girling MyShoutPro 1.2 improper authentication (EDB-5845 / XFDB-43145)
3 days 12 hours ago
A vulnerability was found in Mark Girling MyShoutPro 1.2 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2008-6738. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6742 | Gofoxy Foxy input validation (EDB-5843 / XFDB-43146)
3 days 12 hours ago
A vulnerability classified as problematic has been found in Gofoxy Foxy. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2008-6742. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
El Dorado
3 days 12 hours ago
cohenido
Empire is Allegedly Selling Multiple Databases From the UK and USA
3 days 12 hours ago
Empire is Allegedly Selling Multiple Databases From the UK and USA
Dark Web Informer
CVE-2003-0074 | plptools 0.6 plpnfsd mpmain.c debuglog/errorlog/infolog format string (XFDB-11193 / BID-6715)
3 days 12 hours ago
A vulnerability, which was classified as critical, has been found in plptools 0.6. Affected by this issue is the function debuglog/errorlog/infolog of the file mpmain.c of the component plpnfsd. The manipulation leads to format string.
This vulnerability is handled as CVE-2003-0074. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com