Aggregator
Маленький чип Xiaohong, большие перемены: как Китай преодолел порог в 500 кубитов
1 year 4 months ago
Новый квантовый компьютер бросает очередной вызов IBM и Google.
Cyber 5W
1 year 4 months ago
Cyber 5W
CVE-1999-1375 | Microsoft IIS 3.0/4.0 ASP showfile.asp FileSystemObject privileges management (EDB-19194 / BID-230)
1 year 4 months ago
A vulnerability was found in Microsoft IIS 3.0/4.0. It has been classified as critical. Affected is the function FileSystemObject of the file showfile.asp of the component ASP Handler. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-1999-1375. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Week in review: Veeam Service Provider Console flaws fixed, Patch Tuesday forecast
1 year 4 months ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) Veeam has fixed two vulnerabilities in Veeam Service Provider Console (VSPC), one of which (CVE-2024-42448) may allow remote attackers to achieve code exection on the VSPC server machine. December 2024 Patch Tuesday forecast: The secure future initiative impact It seems like 2024 just started, but the final Patch Tuesday of … More →
The post Week in review: Veeam Service Provider Console flaws fixed, Patch Tuesday forecast appeared first on Help Net Security.
Help Net Security
CVE-2019-13597 | Sahi Pro 8.0.0 Launcher Player_setScriptFile _execute Command command injection (EDB-47110)
1 year 4 months ago
A vulnerability was found in Sahi Pro 8.0.0 and classified as critical. Affected by this issue is the function _execute of the file _s_/sprm/_s_/dyn/Player_setScriptFile of the component Launcher. The manipulation as part of Command leads to command injection.
This vulnerability is handled as CVE-2019-13597. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2001-1354 | Netwin DMail/SurgeFTP NWAuth 2.0/3.0 missing encryption (EDB-21020 / XFDB-6866)
1 year 4 months ago
A vulnerability was found in Netwin DMail and SurgeFTP. It has been declared as problematic. This vulnerability affects unknown code of the component NWAuth 2.0/3.0. The manipulation leads to missing encryption of sensitive data.
This vulnerability was named CVE-2001-1354. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
X
1 year 4 months ago
X
CVE-2018-7182 | ntp up to 4.2.8p11 ntpd ctl_getitem Packet out-of-bounds (SA_18_13 / EDB-45846)
1 year 4 months ago
A vulnerability classified as problematic has been found in ntp up to 4.2.8p11. Affected is the function ctl_getitem of the component ntpd. The manipulation as part of Packet leads to out-of-bounds read.
This vulnerability is traded as CVE-2018-7182. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-12348 | Guizhou Xiaoma Technology jpress 5.1.2 Attachment Upload upload AttachmentUtils.isUnSafe files[] cross site scripting
1 year 4 months ago
A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross site scripting.
This vulnerability is traded as CVE-2024-12348. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
传小米汽车将推15万增程SUV;X 推「无监管」文生图,能生成各种明星;AI 团队悬赏,骗 AI 说我爱你即拿钱 | 极客早知道
1 year 4 months ago
传小米汽车将推15万增程SUV;X 推「无监管」文生图,能生成各种明星;AI 团队悬赏,骗 AI 说我爱你即拿钱 | 极客早知道
CVE-2008-3821 | Cisco IOS up to 12.4 HTTP cross site scripting (EDB-32723 / Nessus ID 17795)
1 year 4 months ago
A vulnerability classified as problematic was found in Cisco IOS up to 12.4. Affected by this vulnerability is an unknown functionality of the component HTTP Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2008-3821. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #454825: Guizhou Xiaoma Technology Co., Ltd. jpress 5.1.2 xss [Accepted]
1 year 4 months ago
Submit #454825 / VDB-287268
dycc
CVE-2024-12347 | Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 Druid Monitoring Interface index.html improper authorization
1 year 4 months ago
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Monitoring Interface. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2024-12347. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2000-1096 | Paul Vixie Cron 3.0 Pl1 crontab -e privileges management (EDB-203 / XFDB-5543)
1 year 4 months ago
A vulnerability was found in Paul Vixie Cron 3.0 Pl1. It has been declared as problematic. This vulnerability affects unknown code of the file crontab. The manipulation of the argument -e leads to improper privilege management.
This vulnerability was named CVE-2000-1096. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #453917: Guangzhou Huayi Intelligent Technology Co., Ltd. JEEWMS <= 1.0.0 unauthorized access [Accepted]
1 year 4 months ago
Submit #453917 / VDB-287267
dycc
CVE-2009-0028 | Linux Kernel 2.6.16.59 access control (Bug 479932 / EDB-32815)
1 year 4 months ago
A vulnerability was found in Linux Kernel 2.6.16.59. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2009-0028. The attack needs to be approached locally. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-12346 | Talentera up to 20241128 byt_cv_manager redirect_url cross site scripting
1 year 4 months ago
A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting.
This vulnerability was named CVE-2024-12346. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The provided PoC only works in Mozilla Firefox. The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #453609: Talentera Talentera for recruitement agencies (CMS) latest Cross Site Scripting [Accepted]
1 year 4 months ago
Submit #453609 / VDB-287266
NikolaT3sla
CVE-2024-12344 | TP-Link VN020 F3v(T) TT_V6.2.1021 FTP USER Command memory corruption
1 year 4 months ago
A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-12344. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com