Aggregator
记一次魔改若依的渗透测试
1 year 1 month ago
Akira
1 year 1 month ago
cohenido
Hunters
1 year 1 month ago
cohenido
警报拉响!新型 SVG 文件钓鱼攻击激增,传统防护体系濒临崩溃
1 year 1 month ago
安全客
M&S Shuts Down Online Orders Amid Ongoing Cyber Incident
1 year 1 month ago
British retailer M&S continues to tackle a cyber incident with online orders now paused for customers
【复现】金蝶天燕应用服务器IIOP远程代码执行漏洞风险通告
1 year 1 month ago
【复现】金蝶天燕应用服务器IIOP远程代码执行漏洞风险通告
1 year 1 month ago
CVE-2024-57375 | Andamiro Pump It Up up to 2.08.3 initialization of resource
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in Andamiro Pump It Up up to 2.08.3. This issue affects some unknown processing. The manipulation leads to incorrect initialization of resource. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-57375. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2023-0342 | MongoDB Ops Manager up to 5.0.20/6.0.11 Diagnostics Archive exposure of sensitive system information to an unauthorized control sphere
1 year 1 month ago
A vulnerability, which was classified as problematic, was found in MongoDB Ops Manager up to 5.0.20/6.0.11. This affects an unknown part of the component Diagnostics Archive. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is uniquely identified as CVE-2023-0342. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-3184 | SourceCodester Sales Tracker Management System 1.0 Users.php?f=save firstname/middlename/lastname/username cross site scripting (ID 172908 / EDB-51513)
1 year 1 month ago
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting.
This vulnerability is handled as CVE-2023-3184. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-34856 | D-Link DI-7500G-CI 19.05.29A HTML File /auth_pic.cgi HTML injection
1 year 1 month ago
A vulnerability classified as problematic has been found in D-Link DI-7500G-CI 19.05.29A. Affected is an unknown function of the file /auth_pic.cgi of the component HTML File Handler. The manipulation leads to HTML injection.
This vulnerability is traded as CVE-2023-34856. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-23913 | actionview Gem on Ruby rails-ujs cross site scripting
1 year 1 month ago
A vulnerability was found in actionview Gem on Ruby. It has been classified as problematic. Affected is an unknown function of the component rails-ujs. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-23913. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Kubernetes 集群安全漏洞遭利用,算力资源面临严重危机
1 year 1 month ago
安全客
CVE-2025-28354 | Entrust Printer Manager Systm up to D3.18.4-3 POST Request path traversal
1 year 1 month ago
A vulnerability classified as critical was found in Entrust Printer Manager Systm up to D3.18.4-3. This vulnerability affects unknown code of the component POST Request Handler. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-28354. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2005-1782 | BookReview add_booklist.htm node cross site scripting (EDB-25731 / Nessus ID 18375)
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in BookReview. Affected by this issue is some unknown functionality of the file add_booklist.htm. The manipulation of the argument node leads to basic cross site scripting.
This vulnerability is handled as CVE-2005-1782. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Windows "inetpub" security fix can be abused to block future updates
1 year 1 month ago
A recent Windows security update that creates an 'inetpub' folder has introduced a new weakness allowing attackers to prevent the installation of future updates. [...]
Lawrence Abrams
CVE-2007-1717 | PHP up to 4.0.0 mail memory corruption (EDB-29784 / Nessus ID 25340)
1 year 1 month ago
A vulnerability was found in PHP up to 4.0.0. It has been classified as critical. This affects the function mail. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2007-1717. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Baltimore City Public Schools data breach affects over 31,000 people
1 year 1 month ago
Baltimore City Public Schools notified tens of thousands of employees and students of a data breach following an incident in February when unknown attackers hacked into its network. [...]
Sergiu Gatlan
North Korean Hackers Spread Malware via Fake Crypto Firms and Job Interview Lures
1 year 1 month ago
North Korea-linked threat actors behind the Contagious Interview have set up front companies as a way to distribute malware during the fake hiring process.
"In this new campaign, the threat actor group is using three front companies in the cryptocurrency consulting industry – BlockNovas LLC (blocknovas[.] com), Angeloper Agency (angeloper[.]com), and SoftGlide LLC (softglide[.]co) – to spread
The Hacker News