Aggregator
【安全圈】太空技术巨头 Maxar 证实攻击者获取了员工数据
2 months 1 week ago
CVE-2015-4165 | Elasticsearch up to 1.5.x Snapshot API access control (ID 132234 / Nessus ID 84410)
2 months 1 week ago
A vulnerability was found in Elasticsearch up to 1.5.x. It has been rated as critical. Affected by this issue is some unknown functionality of the component Snapshot API. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2015-4165. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-4211 | Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows File Name Validator access control (EDB-38289 / ID 123657)
2 months 1 week ago
A vulnerability has been found in Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Name Validator. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2015-4211. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2015-4224 | Cisco Wireless LAN Controller 7.0(240.0) os command injection (CSCuj39474 / ID 38647)
2 months 1 week ago
A vulnerability classified as problematic was found in Cisco Wireless LAN Controller 7.0(240.0). This vulnerability affects unknown code. The manipulation leads to os command injection.
This vulnerability was named CVE-2015-4224. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2015-4238 | Cisco ASA 8.4.7/8.6.1.2 SNMP resource management (Alert 39611 / ID 316049)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Cisco ASA 8.4.7/8.6.1.2. This issue affects some unknown processing of the component SNMP. The manipulation leads to improper resource management.
The identification of this vulnerability is CVE-2015-4238. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2015-4269 | Cisco Unified Communications Manager 10.5(1.99995.9) Tomcat Throttling resource management (CSCuu99709 / ID 316048)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Cisco Unified Communications Manager 10.5(1.99995.9). Affected by this issue is some unknown functionality of the component Tomcat Throttling. The manipulation leads to improper resource management.
This vulnerability is handled as CVE-2015-4269. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-6182 | Sophos Web Appliance up to 4.3.1.1 Report Generator command injection (EDB-42332 / Nessus ID 99237)
2 months 1 week ago
A vulnerability was found in Sophos Web Appliance up to 4.3.1.1 and classified as critical. Affected by this issue is some unknown functionality of the component Report Generator. The manipulation leads to command injection.
This vulnerability is handled as CVE-2017-6182. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
这些值得一看的软件|但不一定有用[241123]
2 months 1 week ago
CVE-2020-20142 | Flexmonster Pivot Table & Charts 2.7.17 To Remote CSV cross site scripting (ID 160604 / EDB-49304)
2 months 1 week ago
A vulnerability classified as problematic was found in Flexmonster Pivot Table & Charts 2.7.17. Affected by this vulnerability is an unknown functionality of the component To Remote CSV. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2020-20142. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5571 | Dotnetindex Professional Download Assistant 0.1 admin/login.asp psw sql injection (EDB-7390 / XFDB-47170)
2 months 1 week ago
A vulnerability was found in Dotnetindex Professional Download Assistant 0.1. It has been classified as critical. This affects an unknown part of the file admin/login.asp. The manipulation of the argument psw leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-5571. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
DoJ seized credit card marketplace PopeyeTools and charges its administrators
2 months 1 week ago
The U.S. seized the stolen credit card marketplace PopeyeTools and charged its operators, this is a major success against cybercrime. The US Department of Justice announced the seizure of PopeyeTools, an illegal carding platform, and charges against three administrators (Abdul Ghaffar (25), of Pakistan; Abdul Sami (35) of Pakistan; and Javed Mirza (37), of Afghanistan). […]
Pierluigi Paganini
CVE-2006-6559 | Lotfian Request For Travel 1.0 productdetails.asp PID sql injection (EDB-2908 / XFDB-30836)
2 months 1 week ago
A vulnerability classified as critical has been found in Lotfian Request For Travel 1.0. This affects an unknown part of the file productdetails.asp. The manipulation of the argument PID leads to sql injection.
This vulnerability is uniquely identified as CVE-2006-6559. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-0744 | Pre Hotels / Resorts Management System user_login.asp sql injection (EDB-31058 / XFDB-39935)
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in Pre Hotels and Resorts Management System. This issue affects some unknown processing of the file user_login.asp. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2008-0744. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-6930 | Ga Soft Rapid Classified 3.1 viewad.asp sql injection (EDB-29133 / XFDB-30449)
2 months 1 week ago
A vulnerability was found in Ga Soft Rapid Classified 3.1. It has been declared as critical. This vulnerability affects unknown code of the file viewad.asp. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2006-6930. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
zTasker v1.99一键定时自动化任务
2 months 1 week ago
软件介绍zTasker是一款完全免费支持定时、热键或条件触发的方式执行多种自动化任务的小工具,支持win7-11。其支持超过100种任务类型,50+种定
CVE-2006-2073 | ISC BIND up to 9.3.2 Zone Transfer TSIG denial of service (VU#955777 / Nessus ID 22311)
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in ISC BIND up to 9.3.2. This issue affects some unknown processing of the component Zone Transfer Handler. The manipulation of the argument TSIG leads to denial of service.
The identification of this vulnerability is CVE-2006-2073. The attack may be initiated remotely. There is no exploit available.
It is recommended to disable the affected component.
vuldb.com
CVE-2006-2007 | Winny 2.0b5.7/2.0b7.1 heap-based overflow (VU#167033 / XFDB-25986)
2 months 1 week ago
A vulnerability classified as critical has been found in Winny 2.0b5.7/2.0b7.1. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2006-2007. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2006-2072 | DeleGate up to 9.0.5 denial of service (VU#955777 / Nessus ID 21293)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in DeleGate. This issue affects some unknown processing. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2006-2072. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-1989 | ClamAV 0.88/0.88.1 HTTP Client get_database memory corruption (VU#599220 / Nessus ID 21496)
2 months 1 week ago
A vulnerability classified as critical has been found in ClamAV 0.88/0.88.1. This affects the function get_database of the component HTTP Client. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2006-1989. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com