Aggregator
PoC Exploit Released for ImageMagick RCE Vulnerability – Update Now
A proof-of-concept (PoC) exploit has been released for a critical remote code execution (RCE) vulnerability in ImageMagick 7’s MagickCore subsystem, specifically affecting the blob I/O (BlobStream) implementation. Security researchers and the ImageMagick team urge all users and organizations to update immediately to prevent exploitation. ImageMagick, a widely used image processing library, was found to contain a heap out-of-bounds write […]
The post PoC Exploit Released for ImageMagick RCE Vulnerability – Update Now appeared first on Cyber Security News.
CVE-2002-1090 | libesmtp 0.8.11 protocol.c read_smtp_response memory corruption (Nessus ID 12382 / ID 74168)
CVE-2002-1114 | Mantis 0.17.0/0.17.1/0.17.2/0.17.3 config_inc2.php privileges management (Nessus ID 14990 / ID 10813)
CVE-2002-1113 | Mantis up to 0.17.3 summary_graph_functions.php g_jpgraph_path privileges management (EDB-21727 / Nessus ID 14990)
CVE-2002-1089 | Oracle Reports 6.0.8/6.0.8.19 rwcgi60 Path information disclosure (EDB-21627 / Nessus ID 57619)
CVE-2002-1111 | Mantis up to 0.17.3 print_all_bug_page.php limit_reporters access control (Nessus ID 14990 / ID 10819)
CVE-2002-1112 | Mantis up to 0.17.3 Authentication Cookie privileges management (Nessus ID 14990 / ID 10818)
How I Hack Websites With Just HTML Injection
Salesloft Drift data breach: Investigation reveals how attackers got in
The attack that resulted in the Salesloft Drift data breach started with the compromise of the company’s GitHub account, Salesloft confirmed this weekend. Supply chain compromise On August 26, the company publicly revealed that earlier that month, a threat actor exfiltrated data from their customers’ Salesforce instances by leveraging stolen OAuth credentials that enable the integration of their Drift (Salesloft) chatbot with said instances. Google Threat Intelligence Group attributed the attack to an attack group … More →
The post Salesloft Drift data breach: Investigation reveals how attackers got in appeared first on Help Net Security.