Aggregator
CLOP
1 year 1 month ago
cohenido
CLOP
1 year 1 month ago
cohenido
CLOP
1 year 1 month ago
cohenido
CVE-2011-4040 | NJStar NJStar Communicator 3.0.11818 memory corruption (VU#819630 / EDB-18196)
1 year 1 month ago
A vulnerability was found in NJStar NJStar Communicator 3.0.11818. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2011-4040. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0467 | Apple Mac OS X 10.4.8 symlink (VU#363112 / EDB-3219)
1 year 1 month ago
A vulnerability was found in Apple Mac OS X 10.4.8 and classified as critical. Affected by this issue is some unknown functionality in the library library/logs/crashreporter/. The manipulation leads to symlink following.
This vulnerability is handled as CVE-2007-0467. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40332 | idcCMS 1.35 moneyRecord_deal.php?mudi=delRecord cross-site request forgery
1 year 1 month ago
A vulnerability was found in idcCMS 1.35. It has been classified as problematic. Affected is an unknown function of the file /admin/moneyRecord_deal.php?mudi=delRecord. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-40332. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40333 | idcCMS 1.35 softBak_deal.php?mudi=del&dataID=2 cross-site request forgery
1 year 1 month ago
A vulnerability was found in idcCMS 1.35. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/softBak_deal.php?mudi=del&dataID=2. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-40333. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40336 | idcCMS 1.35 Image Advertising Management cross site scripting
1 year 1 month ago
A vulnerability classified as problematic has been found in idcCMS 1.35. This affects an unknown part of the component Image Advertising Management. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-40336. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-28828 | Checkmk up to 2.0.0p39/2.1.0p44/2.2.0p28/2.3.0p7 cross-site request forgery
1 year 1 month ago
A vulnerability classified as problematic was found in Checkmk up to 2.0.0p39/2.1.0p44/2.2.0p28/2.3.0p7. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-28828. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40334 | idcCMS 1.35 serverFile_deal.php?mudi=upFileDel&dataID=3 cross-site request forgery
1 year 1 month ago
A vulnerability was found in idcCMS 1.35. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/serverFile_deal.php?mudi=upFileDel&dataID=3. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-40334. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-27095 | Decidim up to 0.27.5/0.28.0 Record cross site scripting (GHSA-529p-jj47-w3m3)
1 year 1 month ago
A vulnerability was found in Decidim up to 0.27.5/0.28.0 and classified as problematic. This issue affects some unknown processing of the component Record Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-27095. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32469 | Decidim up to 0.27.5/0.28.0 GET Parameter per_page cross site scripting (GHSA-7cx8-44pc-xv3q)
1 year 1 month ago
A vulnerability was found in Decidim up to 0.27.5/0.28.0. It has been classified as problematic. Affected is an unknown function of the component GET Parameter Handler. The manipulation of the argument per_page leads to cross site scripting.
This vulnerability is traded as CVE-2024-32469. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38354 | hackmdio codimd up to 2.5.3 HTML Tag Name HTML injection (GHSA-22jv-vch8-2vp9)
1 year 1 month ago
A vulnerability was found in hackmdio codimd up to 2.5.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTML Tag Handler. The manipulation of the argument Name leads to HTML injection.
This vulnerability is known as CVE-2024-38354. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CLOP
1 year 1 month ago
cohenido
CLOP
1 year 1 month ago
cohenido
CLOP
1 year 1 month ago
cohenido
ChatGPT SSRF 漏洞迅速成为攻击者首选攻击载体
1 year 1 month ago
安全客
【安全圈】伪装成安全文档查看器的 DocSwap 恶意软件对全球安卓用户发动攻击
1 year 1 month ago
关键词恶意软件一场名为 “DocSwap” 的复杂恶意软件攻击活动浮出水面,它伪装成一款合法的文档安全与查看应
【安全圈】ChatGPT 漏洞遭超一万个 IP 地址主动利用,美国政府机构惨遭攻击
1 year 1 month ago
关键词攻击者正在积极利用 OpenAI 的 ChatGPT 基础设施中的一个服务器端请求伪造(SSRF)漏洞。