Aggregator
.NET 白名单文件通过反序列化执行系统命令
2 weeks 4 days ago
基于 Cloudflare 的免费网页归档和分享工具
2 weeks 4 days ago
Web Archive 是一个网页归档工具,包含以下几个部分:
浏览器插件:将网页保存为网页快照,并上传到服务端。
服务端: 接收浏览器插件上传的快照,并存储在数据库和存储桶中。
web 客户...
黑海洋
L2 Data: одна база данных может спровоцировать гражданскую войну в США
2 weeks 4 days ago
Как пострадает демократия, если иностранные структуры получат доступ к базе радикалов.
Space Bears
2 weeks 4 days ago
cohenido
李彦宏将做 AI 主题演讲;福特 CEO 爱开小米 SU7 被美国网友怒喷;前员工黑进迪士尼乐园,菜单里加脏话 | 极客早知道
2 weeks 4 days ago
波士顿动力人形机器人已进厂打工;马斯克计划为 xAI 从中东募资;谷歌被俄罗斯罚款 35 位数。
科技爱好者周刊(第 323 期):技术公司的口号比拼
2 weeks 4 days ago
Qilin
2 weeks 4 days ago
cohenido
威努特亮相上汽集团新赛道技术创新高峰论坛,打造智能网联汽车安全新生态
2 weeks 4 days ago
科技驱动,创新引领。
CVE-2024-10605 | code-projects Blood Bank Management System 1.0 /file/request.php cross-site request forgery
2 weeks 4 days ago
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /file/request.php. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-10605. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10607 | code-projects Courier Management System 1.0 /track-result.php Consignment sql injection
2 weeks 4 days ago
A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. The manipulation of the argument Consignment leads to sql injection.
This vulnerability was named CVE-2024-10607. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10608 | code-projects Courier Management System 1.0 /login.php txtusername sql injection
2 weeks 4 days ago
A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection.
The identification of this vulnerability is CVE-2024-10608. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10609 | itsourcecode Tailoring Management System Project 1.0 typeadd.php sex sql injection
2 weeks 4 days ago
A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. The manipulation of the argument sex leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10609. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10610 | ESAFENET CDG 5 ProtocolService.java delProtocol id sql injection
2 weeks 4 days ago
A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-10610. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10611 | ESAFENET CDG 5 PrintScreenListService.java delProtocol id sql injection
2 weeks 4 days ago
A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2024-10611. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10612 | ESAFENET CDG 5 HookInvalidCourseService.java removeHookInvalidCourse id sql injection
2 weeks 4 days ago
A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2024-10612. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10613 | ESAFENET CDG 5 SystemEncryptPolicyService.java delSystemEncryptPolicy id sql injection
2 weeks 4 days ago
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/system/SystemEncryptPolicyService.java. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2024-10613. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10615 | Tongda OA 2017 up to 11.10 delete_data_attach.php RUN_ID sql injection
2 weeks 4 days ago
A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/query/list/input_form/delete_data_attach.php. The manipulation of the argument RUN_ID leads to sql injection.
This vulnerability is handled as CVE-2024-10615. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-6480 | SIP Reviews Shortcode for WooCommerce Plugin up to 1.2.3 on WordPress cross site scripting
2 weeks 4 days ago
A vulnerability was found in SIP Reviews Shortcode for WooCommerce Plugin up to 1.2.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-6480. The attack may be launched remotely. There is no exploit available.
vuldb.com
Нулевая активность при полной загрузке: новый баг Windows 11
2 weeks 4 days ago
Ошибка затронула пользователей последней версии 24H2.