Aggregator
疑似有国家背景的APT组织利用0Day漏洞针对Ivanti CSA展开攻击—每周威胁情报动态第196期(10.11-10.17)
2 months 3 weeks ago
APT组织Lazarus 在Rootkit(获取内核权限)攻击中使用了微软的0day漏洞;APT组织Kimsuky利用软件公司产品安装程序进行伪装展开攻击;NoName057(16)组织DDoSia项目持续更新;
5100 арестов и $59 млн: Интерпол наносит удар по глобальной сети нелегальных букмекеров
2 months 3 weeks ago
Международная операция раскрывает масштабы теневых букмекеров.
Radiant Capital 攻击事件分析
2 months 3 weeks ago
RadiantCapital项目被攻击,共造成50M USD的损失。主要原因是 Radiant 的核心人员安全意识不足,导致攻击者构造虚假的前端骗取核心人员签名攻击交易。
PT Rules: открытая платформа для глобальной кибербезопасности
2 months 3 weeks ago
Positive Technologies запустила проект с открытым кодом для проактивного обнаружения киберугроз.
CVE-2016-6977 | Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053 memory corruption (APSB16-33 / Nessus ID 94074)
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2016-6977. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-1124 | Podcast Generator up to 1.0 Parser absoluteurl code injection (EDB-5200 / BID-28038)
2 months 3 weeks ago
A vulnerability was found in Podcast Generator up to 1.0. It has been classified as critical. This affects an unknown part of the component Parser. The manipulation of the argument absoluteurl leads to code injection.
This vulnerability is uniquely identified as CVE-2008-1124. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1074 | Group E 1.6.41 lib/head_auth.php CFG[PREPEND_FILE] code injection (EDB-5197 / BID-28024)
2 months 3 weeks ago
A vulnerability has been found in Group E 1.6.41 and classified as critical. This vulnerability affects unknown code in the library lib/head_auth.php. The manipulation of the argument CFG[PREPEND_FILE] leads to code injection.
This vulnerability was named CVE-2008-1074. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1121 | eazyPortal 1.0 index.php sql injection (EDB-5196 / BID-28019)
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in eazyPortal 1.0. Affected is an unknown function of the file index.php. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2008-1121. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1122 | Dream4 Koobi Pro 5.7 Downloads Module index.php categ sql injection (EDB-5198 / XFDB-40903)
2 months 3 weeks ago
A vulnerability has been found in Dream4 Koobi Pro 5.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Downloads Module. The manipulation of the argument categ leads to sql injection.
This vulnerability is known as CVE-2008-1122. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1123 | SiteBuilder SiteBuilder Elite 1.2 CarpPath code injection (EDB-5199 / BID-28036)
2 months 3 weeks ago
A vulnerability was found in SiteBuilder SiteBuilder Elite 1.2 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument CarpPath leads to code injection.
This vulnerability is handled as CVE-2008-1123. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1061 | WordPress Sniplets Plugin 1.1.2 warning.php page cross site scripting (EDB-5194 / XFDB-40830)
2 months 3 weeks ago
A vulnerability has been found in WordPress Sniplets Plugin 1.1.2 and classified as problematic. This vulnerability affects unknown code of the file warning.php. The manipulation of the argument page leads to cross site scripting.
This vulnerability was named CVE-2008-1061. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1077 | Mamboportal.com Simpleboard 1.0.3 Stable index.php catid sql injection (EDB-5195 / BID-28018)
2 months 3 weeks ago
A vulnerability was found in Mamboportal.com Simpleboard 1.0.3 Stable. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument catid leads to sql injection.
This vulnerability is known as CVE-2008-1077. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
На Марсе нашли идеальное место, где могли бы жить микроскопические инопланетяне
2 months 3 weeks ago
Секреты прошлого Красной планеты скрыты под тонким слоем льда.
CVE-2006-1586 | Internet Solutions Professionals Site Man Login admin_login.asp pass sql injection (EDB-27552 / XFDB-25595)
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Internet Solutions Professionals Site Man. Affected by this issue is some unknown functionality of the file admin_login.asp of the component Login. The manipulation of the argument pass leads to sql injection.
This vulnerability is handled as CVE-2006-1586. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.
vuldb.com
.NET 一款内网渗透环境下切换不同身份启动进程的工具
2 months 3 weeks ago
.NET 安全攻防知识交流社区
2 months 3 weeks ago
.NET基础安全视频 | 生成强名称程序集规避防护规则
2 months 3 weeks ago
派早报:OPPO 召开 2024 年开发者大会、亚马逊 Kindle 系列更新等
2 months 3 weeks ago
你可能错过的新鲜事OPPO 召开 2024 年开发者大会10 月 17 日,OPPO 召开 2024 年开发者大会,正式发布了 ColorOS 15,引入了「一键问屏」功能等功能。据悉,「超级小布
微信推「附近的工作」功能;BOSS 直聘进军婚恋交友,推「看准」App;Prada 设计美国登月宇航服 | 极客早知道
2 months 3 weeks ago
特斯拉 Semi 电动卡车将在全球范围内上市;小米 SU7 汽车交付将在 11 月突破 10 万辆;台积电发布三季度财报:营收达到 235 亿美元创新高