Aggregator
.NET 一种尚未公开绕过 SQL 全局防注入拦截的方法
4 months 3 weeks ago
在.NET安全中,SQL注入攻击一直是安全领域的一个重要话题。
Lockbit
4 months 3 weeks ago
cohenido
Lockbit
4 months 3 weeks ago
cohenido
打靶日记--Tr0ll
4 months 3 weeks ago
打靶(红温)日记
CVE-2011-4580 | Red Hat JBoss 4.3.0/5.0.0/5.0.1/5.1.0/5.1.1 Enterprise Portal Platform cross site scripting (RHSA-2011:1822 / SA47119)
4 months 3 weeks ago
A vulnerability has been found in Red Hat JBoss 4.3.0/5.0.0/5.0.1/5.1.0/5.1.1 and classified as critical. This vulnerability affects unknown code of the component Enterprise Portal Platform. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2011-4580. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4580 | Red Hat JBoss Enterprise Portal Platform 5.1.1 Portlet to Category UIApplicationList.gtmpl cross site scripting (RHSA-2011-1822 / SA47119)
4 months 3 weeks ago
A vulnerability was found in Red Hat JBoss Enterprise Portal Platform 5.1.1 and classified as problematic. This issue affects some unknown processing of the file web/portal/src/main/webapp/groovy/portal/webui/application/UIApplicationList.gtmpl of the component Portlet to Category Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2011-4580. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4580 | Red Hat JBoss Enterprise Portal Platform 5.1.1 Portlet Title cross site scripting (RHSA-2011-1822 / SA47119)
4 months 3 weeks ago
A vulnerability was found in Red Hat JBoss Enterprise Portal Platform 5.1.1. It has been classified as problematic. Affected is an unknown function of the component Portlet Title Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2011-4580. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4580 | Red Hat JBoss Enterprise Portal Platform 5.1.1 Node Label cross site scripting (RHSA-2011-1822 / SA47119)
4 months 3 weeks ago
A vulnerability was found in Red Hat JBoss Enterprise Portal Platform 5.1.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Node Label Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2011-4580. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4580 | Red Hat JBoss Enterprise Portal Platform 5.1.1 RSS Reader Gadget cross site scripting (RHSA-2011-1822 / SA47119)
4 months 3 weeks ago
A vulnerability was found in Red Hat JBoss Enterprise Portal Platform 5.1.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component RSS Reader Gadget. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2011-4580. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4580 | Red Hat JBoss Enterprise Portal Platform 5.1.1 UIFormDateTimeInput cross site scripting (RHSA-2011-1822 / SA47119)
4 months 3 weeks ago
A vulnerability classified as problematic has been found in Red Hat JBoss Enterprise Portal Platform 5.1.1. This affects an unknown part of the component UIFormDateTimeInput. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2011-4580. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-4580 | Red Hat JBoss Enterprise Portal Platform 5.1.1 Group Description cross site scripting (RHSA-2011-1822 / SA47119)
4 months 3 weeks ago
A vulnerability classified as problematic was found in Red Hat JBoss Enterprise Portal Platform 5.1.1. This vulnerability affects unknown code of the component Group Description Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2011-4580. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0058 | Red Hat JBoss Enterprise Application Platform 6.0.0/6.0.1/6.1.0/6.2.0 Security Audit cryptographic issues (RHSA-2014:0204 / Nessus ID 72678)
4 months 3 weeks ago
A vulnerability was found in Red Hat JBoss Enterprise Application Platform 6.0.0/6.0.1/6.1.0/6.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Security Audit Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-0058. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-2134 | Martin Nagy bind-dyndb-ldap 0.1.0/0.2.0/1.0.0/1.1.0 ldap_helper.c handle_connection_error resource management (RHSA-2012:0683 / Nessus ID 68530)
4 months 3 weeks ago
A vulnerability was found in Martin Nagy bind-dyndb-ldap 0.1.0/0.2.0/1.0.0/1.1.0 and classified as problematic. Affected by this issue is the function handle_connection_error of the file ldap_helper.c. The manipulation leads to improper resource management.
This vulnerability is handled as CVE-2012-2134. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-3712 | SUSE Studio Onsite up to 1.3.3 cryptographic issues (SA57050)
4 months 3 weeks ago
A vulnerability was found in SUSE Studio Onsite up to 1.3.3. It has been classified as critical. This affects an unknown part. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2013-3712. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-2205 | McAfee ePolicy Orchestrator 4.6.7 ePolicy Orchestrator XML access control (Nessus ID 72729 / ID 121818)
4 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in McAfee ePolicy Orchestrator 4.6.7. This affects an unknown part of the component ePolicy Orchestrator XML Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2014-2205. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2011-2941 | Red Hat JBoss 4.3.0/5.0.0/5.0.1/5.1.0/5.1.1 Enterprise Portal Platform initialURI input validation (RHSA-2011:1822 / SA47119)
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Red Hat JBoss 4.3.0/5.0.0/5.0.1/5.1.0/5.1.1. This affects an unknown part of the component Enterprise Portal Platform. The manipulation of the argument initialURI leads to improper input validation.
This vulnerability is uniquely identified as CVE-2011-2941. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-7332 | Microsoft Internet Explorer XMLDOM ActiveX Control resource management (XFDB-91485 / SBV-43427)
4 months 3 weeks ago
A vulnerability classified as problematic was found in Microsoft Internet Explorer. Affected by this vulnerability is an unknown functionality of the component XMLDOM ActiveX Control. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2013-7332. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-0033 | Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting Session Hijacking input validation (Revision 1149220 / Nessus ID 72690)
4 months 3 weeks ago
A vulnerability classified as critical has been found in Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37. Affected is the function disableURLRewriting of the file org/apache/catalina/connector/coyoteadapter.java. The manipulation leads to improper input validation (Session Hijacking).
This vulnerability is traded as CVE-2014-0033. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2013-6204 | HP Application Information Optimizer 7.1 Web Console memory corruption
4 months 3 weeks ago
A vulnerability was found in HP Application Information Optimizer 7.1 and classified as critical. This issue affects some unknown processing of the component Web Console. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2013-6204. The attack may be initiated remotely. There is no exploit available.
vuldb.com