Aggregator
CVE-2017-5492 | WordPress up to 4.7.0 class-wp-screen.php cross-site request forgery (Nessus ID 96606 / ID 175955)
1 month 1 week ago
A vulnerability marked as problematic has been reported in WordPress. This vulnerability affects unknown code of the file wp-admin/includes/class-wp-screen.php. The manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2017-5492. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2017-5493 | WordPress up to 4.7.0 Multisite API ms-functions.php cryptographic issue (EDB-40968 / Nessus ID 96606)
1 month 1 week ago
A vulnerability described as critical has been identified in WordPress. This issue affects some unknown processing of the file wp-includes/ms-functions.php of the component Multisite API. The manipulation results in cryptographic issues.
This vulnerability is reported as CVE-2017-5493. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
vuldb.com
CVE-2017-5480 | b2evolution up to 6.8.3 inc/files/files.ctrl.php fm_selected path traversal (BID-95454 / ID 802129)
1 month 1 week ago
A vulnerability classified as critical was found in b2evolution up to 6.8.3. The affected element is an unknown function of the file inc/files/files.ctrl.php. Such manipulation of the argument fm_selected leads to path traversal.
This vulnerability is traded as CVE-2017-5480. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-5494 | b2evolution up to 6.8.3 SWF File comment/avatar cross site scripting (BID-95452 / ID 802129)
1 month 1 week ago
A vulnerability, which was classified as problematic, has been found in b2evolution up to 6.8.3. The impacted element is an unknown function of the component SWF File Handler. Performing a manipulation of the argument comment/avatar results in cross site scripting.
This vulnerability is known as CVE-2017-5494. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2016-7904 | CMS Made Simple up to 2.1.5 admin/adduser.php cross-site request forgery (BID-95453 / ID 103332)
1 month 1 week ago
A vulnerability has been found in CMS Made Simple up to 2.1.5 and classified as problematic. This impacts an unknown function of the file admin/adduser.php. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2016-7904. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2017-5223 | PHPMailer up to 5.2.21 msgHTML information disclosure (EDB-43056 / Nessus ID 96471)
1 month 1 week ago
A vulnerability was found in PHPMailer up to 5.2.21 and classified as problematic. Affected is the function msgHTML. The manipulation results in information disclosure.
This vulnerability was named CVE-2017-5223. The attack may be performed from remote. In addition, an exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2017-5515 | GeniXCMS up to 0.0.8 User Prompt cross site scripting (ID 63 / BID-95623)
1 month 1 week ago
A vulnerability categorized as problematic has been discovered in GeniXCMS up to 0.0.8. The impacted element is an unknown function of the component User Prompt Handler. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2017-5515. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2017-5516 | GeniXCMS up to 0.0.8 User Forms cross site scripting (ID 65 / BID-95622)
1 month 1 week ago
A vulnerability identified as problematic has been detected in GeniXCMS up to 0.0.8. This affects an unknown function of the component User Forms. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2017-5516. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2017-5517 | GeniXCMS up to 0.0.8 author.control.php Type sql injection (ID 66 / BID-95455)
1 month 1 week ago
A vulnerability labeled as critical has been found in GeniXCMS up to 0.0.8. This impacts an unknown function of the file author.control.php. Executing a manipulation of the argument Type can lead to sql injection.
The identification of this vulnerability is CVE-2017-5517. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-5518 | GeniXCMS up to 0.0.8 Media-File Upload server-side request forgery (ID 64 / BID-95462)
1 month 1 week ago
A vulnerability marked as critical has been reported in GeniXCMS up to 0.0.8. Affected is an unknown function of the component Media-File Upload. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2017-5518. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2017-5519 | GeniXCMS up to 0.0.8 Posts.class.php ID sql injection (ID 67 / BID-95458)
1 month 1 week ago
A vulnerability described as critical has been identified in GeniXCMS up to 0.0.8. Affected by this vulnerability is an unknown functionality of the file Posts.class.php. The manipulation of the argument ID results in sql injection.
This vulnerability is identified as CVE-2017-5519. The attack can be executed remotely. There is not any exploit available.
vuldb.com
Money Message
1 month 1 week ago
You must login to view this content
cohenido
Most Remediation Programs Never Confirm the Fix Actually Worked
1 month 1 week ago
Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed.
Mandiant's M-Trends 2026 report puts the mean time to exploit at an estimated negative seven days. The Verizon 2025 DBIR puts median time to remediate edge device vulnerabilities at 32 days. These numbers have understandably driven the industry toward a clear
The Hacker News
10 секунд на подумать: Google встраивает в Android паузу перед запуском TikTok и Instagram — как это работает
1 month 1 week ago
Что такое Pause Point и зачем он нужен в Android 17.
ClickFix Evolves with 10-Year-Old Open-Source Python SOCKS5 Proxy
1 month 1 week ago
A cyberattack campaign that tricks users into running malicious commands on their own computers has taken a dangerous new turn. The technique, known as “ClickFix,” has been circulating for some time, but a recent incident revealed that attackers are now pairing it with a 10-year-old open-source Python tool to create a far more resilient form […]
The post ClickFix Evolves with 10-Year-Old Open-Source Python SOCKS5 Proxy appeared first on Cyber Security News.
Tushar Subhra Dutta
Один взлом — и заводы встали. Что будет с поставками инсулина, вакцин и онкопрепаратов, если West Pharmaceutical не восстановится вовремя
1 month 1 week ago
Почему атака на производителя упаковки для лекарств может ударить по пациентам по всему миру.
【安全圈】Exim 新 BDAT 漏洞致 GnuTLS 构建面临代码执行风险
1 month 1 week ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
【安全圈】Windows 11遭新型BitUnlocker降级攻击:5分钟内可解密加密磁盘
1 month 1 week ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
【安全圈】苹果修复 macOS 和 iOS 系统数十个漏洞
1 month 1 week ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。