Aggregator
.NET内网实战:通过指定的COM接口执行命令绕过UAC
1 week 5 days ago
CVE-2004-1789 | ZyWALL up to 4.07 containing cross site scripting (EDB-23527 / Nessus ID 11492)
1 week 5 days ago
A vulnerability classified as problematic was found in ZyWALL up to 4.07. Affected by this vulnerability is an unknown functionality of the file containing. The manipulation leads to basic cross site scripting.
This vulnerability is known as CVE-2004-1789. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to disable the affected component.
vuldb.com
Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams
1 week 5 days ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Patching problems: The “return” of a Windows Themes spoofing vulnerability Despite two patching attempts, a security issue that may allow attackers to compromise Windows user’s NTLM (authentication) credentials via a malicious Windows themes file still affects Microsoft’s operating system, 0patch researchers have discovered. Black Basta operators phish employees via Microsoft Teams Black Basta ransomware affiliates are still trying to trick … More →
The post Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams appeared first on Help Net Security.
Help Net Security
CVE-2016-5048 | ReadyDesk 9.1 chat/staff/default.aspx username sql injection (VU#294272 / BID-92487)
1 week 5 days ago
A vulnerability classified as very critical was found in ReadyDesk 9.1. This vulnerability affects unknown code of the file chat/staff/default.aspx. The manipulation of the argument username leads to sql injection.
This vulnerability was named CVE-2016-5048. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2016-0150 | Microsoft Windows 10 HTTP.sys HTTP Request data processing (MS16-049 / Nessus ID 90442)
1 week 5 days ago
A vulnerability classified as critical was found in Microsoft Windows 10. This vulnerability affects unknown code in the library HTTP.sys. The manipulation as part of HTTP Request leads to data processing error.
This vulnerability was named CVE-2016-0150. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
2024第四届“网鼎杯”白虎组 writeup
1 week 5 days ago
英伟达替下英特尔,进入道指;苹果超百亿投资卫星通信公司;聚美优品官网失效,陈欧已进军短剧 | 极客早知道
1 week 5 days ago
微软斥资近 100 亿美元租用 CoreWeave AI 服务器;赛力斯汽车发布声明:回应昆明问界 M9 事故;大疆 Mic Mini 紧凑型麦克风曝光
CVE-2016-0151 | Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 CSRSS access control (MS16-048 / EDB-39740)
1 week 5 days ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2. This issue affects some unknown processing of the component CSRSS. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2016-0151. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
首次披露:美国CIA曾针对委内瑞拉实施网络战欲挑动颠覆活动
1 week 5 days ago
CIA的网攻策略观察
CVE-2008-3711 | PHPArcadeScript 4.0 index.php cat sql injection (EDB-6255 / XFDB-44523)
1 week 5 days ago
A vulnerability classified as critical has been found in PHPArcadeScript 4.0. This affects an unknown part of the file index.php. The manipulation of the argument cat leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-3711. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-3713 | PHPBasket product.php pro_id sql injection (EDB-6258 / XFDB-44524)
1 week 5 days ago
A vulnerability, which was classified as critical, has been found in PHPBasket. This issue affects some unknown processing of the file product.php. The manipulation of the argument pro_id leads to sql injection.
The identification of this vulnerability is CVE-2008-3713. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-3734 | Ipswitch Ws Ftp Home 2007.0.0.2 format string (EDB-6257 / XFDB-44512)
1 week 5 days ago
A vulnerability has been found in Ipswitch Ws Ftp Home 2007.0.0.2 and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to format string.
This vulnerability is known as CVE-2008-3734. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-3795 | Ipswitch WS_FTP Home client memory corruption (EDB-6257 / XFDB-44744)
1 week 5 days ago
A vulnerability, which was classified as very critical, has been found in Ipswitch WS_FTP Home client. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2008-3795. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6022 | Xnova 0.8 ugamela_root_path code injection (EDB-6254 / XFDB-44513)
1 week 5 days ago
A vulnerability was found in Xnova 0.8 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument ugamela_root_path leads to code injection.
This vulnerability is handled as CVE-2008-6022. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6023 | Xnova 0.8 xnova_root_path code injection (EDB-6254 / XFDB-48533)
1 week 5 days ago
A vulnerability was found in Xnova 0.8. It has been classified as critical. This affects an unknown part. The manipulation of the argument xnova_root_path leads to code injection.
This vulnerability is uniquely identified as CVE-2008-6023. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-6287 | Rejetto HTTP File Server up to 2.x parserLib.pas findMacroMarker code injection (ID 128243 / VU#251276)
1 week 5 days ago
A vulnerability was found in Rejetto HTTP File Server up to 2.x and classified as critical. This issue affects the function findMacroMarker in the library parserLib.pas. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2014-6287. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Quickpost: The Electric Energy Consumption Of A Wired Doorbell
1 week 5 days ago
Quickpost: The Electric Energy Consumption Of A Wired Doorbell I have a classic wi
Microsoft Outlook workaround fixes freezes when copying text
1 week 5 days ago
error code: 1106
Microsoft SharePoint RCE bug exploited to breach corporate network
1 week 5 days ago
error code: 1106