Aggregator
[Meachines] [Medium] Sniper RFI包含远程SMB+ powershell用户横向+CHM武器化权限提升
1 year 8 months ago
#RFI包含远程SMB #powershell用户横向 #CHM武器化权限提升
CVE-2007-3360 | BitchX 1.1-final Hooks privileges management (EDB-4087 / XFDB-34969)
1 year 8 months ago
A vulnerability was found in BitchX 1.1-final. It has been classified as problematic. This affects an unknown part of the component Hooks. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2007-3360. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to disable the affected component.
vuldb.com
openECSC 2024 - Final Round
1 year 8 months ago
Name: openECSC 2024 - Final Round (an openECSC - CybersecNatLab event.)
Date: Sept. 21, 2024, 10 a.m. — 22 Sept. 2024, 10:00 UTC [add to calendar]
Format: Jeopardy
On-site
Offical URL: https://open.ecsc2024.it/
Rating weight: 0
Event organizers: ECSC2024
Date: Sept. 21, 2024, 10 a.m. — 22 Sept. 2024, 10:00 UTC [add to calendar]
Format: Jeopardy
On-site
Offical URL: https://open.ecsc2024.it/
Rating weight: 0
Event organizers: ECSC2024
Haruulzangi CTF 2024 Round 2
1 year 8 months ago
Name: Haruulzangi CTF 2024 Round 2 (an Haruulzangi event.)
Date: Sept. 22, 2024, 4 a.m. — 22 Sept. 2024, 08:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Nest education IT School, Ulaanbaatar , Mongolia
Offical URL: https://dashboard.haruulzangi.mn/
Rating weight: 0.00
Event organizers: haruulzangi-organizers
Date: Sept. 22, 2024, 4 a.m. — 22 Sept. 2024, 08:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Nest education IT School, Ulaanbaatar , Mongolia
Offical URL: https://dashboard.haruulzangi.mn/
Rating weight: 0.00
Event organizers: haruulzangi-organizers
【安全圈】代号「神谕的黄鹂」Ubuntu 24.10测试版发布 将在10月10日推出正式版(非LTS)
1 year 8 months ago
【安全圈】警惕新网络钓鱼手法:虚假 CAPTCHA 页面诱骗用户安装 Lumma Stealer 恶意软件
1 year 8 months ago
【安全圈】朝鲜 APT 在网络间谍攻击中绕过 DMARC 电子邮件策略
1 year 8 months ago
【安全圈】黑客声称对戴尔公司进行了数据泄露,曝光超过10,000名员工信息
1 year 8 months ago
CVE-2014-4162 | Zyxel P-660HW T1 cross-site request forgery (Exploit 126812 / EDB-33518)
1 year 8 months ago
A vulnerability classified as critical was found in Zyxel P-660HW T1. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2014-4162. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
仅剩最后1天!SDC 2024 早鸟票即将售罄
1 year 8 months ago
Android app三种常见抓包场景及案例分析
1 year 8 months ago
看雪论坛作者ID:scllqk
CVE-2022-22947 | VMware Spring Cloud Gateway up to 3.0.6/3.1.0 Actuator Endpoint code injection (EDB-50799)
1 year 8 months ago
A vulnerability was found in VMware Spring Cloud Gateway up to 3.0.6/3.1.0. It has been classified as very critical. This affects an unknown part of the component Actuator Endpoint. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2022-22947. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Network Exposure Function NEF code injection (EDB-50799)
1 year 8 months ago
A vulnerability, which was classified as very critical, has been found in Oracle Communications Cloud Native Core Network Exposure Function 22.1.0. Affected by this issue is some unknown functionality of the component NEF. The manipulation leads to code injection.
This vulnerability is handled as CVE-2022-22947. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-1388 | F5 BIG-IP up to 13.1.4/14.1.4.5/15.1.5.0/16.1.2.1 iControl REST Authentication /mgmt/tm/util/bash missing authentication (K23605346 / EDB-50932)
1 year 8 months ago
A vulnerability, which was classified as very critical, has been found in F5 BIG-IP up to 13.1.4/14.1.4.5/15.1.5.0/16.1.2.1. Affected by this issue is some unknown functionality of the file /mgmt/tm/util/bash of the component iControl REST Authentication. The manipulation leads to missing authentication.
This vulnerability is handled as CVE-2022-1388. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-30525 | ZyXEL USG FLEX 50 CGI Program os command injection (EDB-50946)
1 year 8 months ago
A vulnerability classified as critical has been found in ZyXEL USG FLEX 100, USG FLEX 200, USG FLEX 500, USG FLEX 700, USG FLEX 20 and USG FLEX 50. Affected is an unknown function of the component CGI Program Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2022-30525. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Binding Support Function BSF code injection (EDB-50799)
1 year 8 months ago
A vulnerability, which was classified as very critical, was found in Oracle Communications Cloud Native Core Binding Support Function 22.1.3. Affected is an unknown function of the component BSF. The manipulation leads to code injection.
This vulnerability is traded as CVE-2022-22947. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Console 22.2.0 CNC Console code injection (EDB-50799)
1 year 8 months ago
A vulnerability has been found in Oracle Communications Cloud Native Core Console 22.2.0 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component CNC Console. The manipulation leads to code injection.
This vulnerability is known as CVE-2022-22947. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Network Repository Function NRF code injection (EDB-50799)
1 year 8 months ago
A vulnerability was found in Oracle Communications Cloud Native Core Network Repository Function 22.1.2/22.2.0 and classified as very critical. Affected by this issue is some unknown functionality of the component NRF. The manipulation leads to code injection.
This vulnerability is handled as CVE-2022-22947. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-22947 | Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP code injection (EDB-50799)
1 year 8 months ago
A vulnerability was found in Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1. It has been classified as very critical. This affects an unknown part of the component SEPP. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2022-22947. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com