Aggregator
【开源情报分析】大鹅如何将朝军队运送到乌战争前线
1 year 1 month ago
Submit #434933: Tenda AC15 V15.03.05.19 Buffer Overflow [Accepted]
1 year 1 month ago
Submit #434933 / VDB-282677
theRaz0r
Submit #434932: Tenda AC15 V15.03.05.19 Buffer Overflow [Accepted]
1 year 1 month ago
Submit #434932 / VDB-282676
theRaz0r
ЦРУ в цифровой войне: тайные попытки США подорвать власть в Венесуэле
1 year 1 month ago
Закулисная игра спецслужб и её непредвиденные результаты.
CVE-2024-10660 | ESAFENET CDG 5 HookService.java deleteHook hookId sql injection
1 year 1 month ago
A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10660. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10659 | ESAFENET CDG 5 CDGAuthoriseTempletService.java delSystemEncryptPolicy id sql injection
1 year 1 month ago
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthoriseTempletService.java. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2024-10659. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
黑客组织TeamTNT发起针对云原生环境的大规模攻击活动——每周威胁情报动态第198期(10.25-10.31)
1 year 1 month ago
APT组织Lazarus 在Rootkit(获取内核权限)攻击中使用了微软的0day漏洞;APT组织Kimsuky利用软件公司产品安装程序进行伪装展开攻击;NoName057(16)组织DDoSia项目持续更新;
Nacos 综合利用工具推荐
1 year 1 month ago
Submit #434897: Projectworlds Online Time Table Generator v1.0 SQL Injection [Duplicate]
1 year 1 month ago
Submit #434897 / VDB-251553
G__K
研究发现猴子永远也写不出莎士比亚著作
1 year 1 month ago
无限猴子定理(Infinite monkey theorem)认为,让一只猴子在打字机上随机地按键,当按键时间达到无穷时,几乎必然能够打出任何给定的文字,比如莎士比亚的全套著作。澳大利亚的两位数学家挑战了这一理论,他们发现猴子靠随机打字写出莎士比亚戏剧、十四行诗和诗歌所需的时间比宇宙的寿命还要长。数学家称,虽然无限猴子定理在理论上是正确的,但实际上不可行,有误导性。研究发现,一只黑猩猩在其一生中成功输入“bananas”这个词的几率为 5%。一只黑猩猩写出一个随机句子的概率——例如“我黑猩猩,故我在(I chimp, therefore I am)”——是 1000 万亿分之一。即使到宇宙的尽头,猴子也写不出莎士比亚的作品。
CVE-2024-10658 | Tongda OA up to 11.10 check_seal.php ID sql injection
1 year 1 month ago
A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2024-10658. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10657 | Tongda OA up to 11.10 prcs_info.php RUN_ID sql injection
1 year 1 month ago
A vulnerability classified as critical has been found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/approve_center/prcs_info.php. The manipulation of the argument RUN_ID leads to sql injection.
This vulnerability is traded as CVE-2024-10657. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10656 | Tongda OA 2017 up to 11.9 /pda/meeting/apply.php mr_id sql injection
1 year 1 month ago
A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the file /pda/meeting/apply.php. The manipulation of the argument mr_id leads to sql injection.
The identification of this vulnerability is CVE-2024-10656. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10655 | Tongda OA 2017 up to 11.9 /pda/reportshop/new.php repid sql injection
1 year 1 month ago
A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file /pda/reportshop/new.php. The manipulation of the argument repid leads to sql injection.
This vulnerability was named CVE-2024-10655. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #434863: ESAFENET CDG V5 SQL Injection [Accepted]
1 year 1 month ago
Submit #434863 / VDB-282675
0menc
Submit #434862: ESAFENET CDG V5 SQL Injection [Accepted]
1 year 1 month ago
Submit #434862 / VDB-282674
0menc
CVE-2021-47078 | Linux Kernel up to 5.12.6 RDMA lib/refcount.c rxe_qp_do_cleanup use after free
1 year 1 month ago
A vulnerability was found in Linux Kernel up to 5.12.6. It has been classified as problematic. Affected is the function rxe_qp_do_cleanup in the library lib/refcount.c of the component RDMA. The manipulation leads to use after free.
This vulnerability is traded as CVE-2021-47078. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-45896 | Linux Kernel up to 6.5.10 ntfs3 out-of-bounds
1 year 1 month ago
A vulnerability was found in Linux Kernel up to 6.5.10. It has been classified as problematic. Affected is an unknown function of the component ntfs3. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2023-45896. It is possible to launch the attack on the physical device. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48237 | WTCMS 1.0 HomebaseController.class.php access control (Issue 15)
1 year 1 month ago
A vulnerability was found in WTCMS 1.0. It has been classified as critical. Affected is an unknown function of the file \Common\Controller\HomebaseController.class.php. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-48237. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com