Aggregator
.NET 11月份红队武器库工具汇总(上)
1 year 4 months ago
NSO Group admits cutting off 10 customers because they abused its Pegasus spyware, say unsealed court documents
1 year 4 months ago
On Thursday, WhatsApp scored a legal victory by convincing a U.S. federal judge to publicly release
CVE-2024-45670 | IBM Security SOAR 51.0.1.0 password recovery
1 year 4 months ago
A vulnerability classified as problematic was found in IBM Security SOAR 51.0.1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery.
This vulnerability is known as CVE-2024-45670. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9186 | FunnelKit Recover WooCommerce Cart Abandonment up to 3.2.x on WordPress bwfan-track-id sql injection
1 year 4 months ago
A vulnerability classified as critical was found in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing and Marketing Automation Plugin up to 3.2.x on WordPress. This vulnerability affects unknown code. The manipulation of the argument bwfan-track-id leads to sql injection.
This vulnerability was named CVE-2024-9186. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Granny Bots, Microsoft, Shrinklocker, SlugResin, BlueSky, Aaran Leyland, and More... - SWN #431
1 year 4 months ago
Welcome to the Security Weekly Podcast Network, your all-in-one so
CVE-2008-6314 | phpBB Tag Board up to 4.0 tag_board.php id sql injection (EDB-7386 / XFDB-47163)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in phpBB Tag Board up to 4.0. Affected is an unknown function of the file tag_board.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2008-6314. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6498 | Apachefriends xampp 1.6.8 htaccess cross-site request forgery (EDB-7384 / XFDB-47201)
1 year 4 months ago
A vulnerability was found in Apachefriends xampp 1.6.8. It has been rated as critical. This issue affects some unknown processing of the component htaccess. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2008-6498. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6499 | Apachefriends xampp 1.6.8 code injection (EDB-7384 / XFDB-47202)
1 year 4 months ago
A vulnerability classified as critical has been found in Apachefriends xampp 1.6.8. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2008-6499. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6884 | XOOPS 2.3.1 blocks.php xoopsConfig[language] path traversal (EDB-7380 / Nessus ID 35278)
1 year 4 months ago
A vulnerability classified as critical has been found in XOOPS 2.3.1. Affected is an unknown function in the library xoops_lib/modules/protector/ of the file blocks.php. The manipulation of the argument xoopsConfig[language] leads to path traversal.
This vulnerability is traded as CVE-2008-6884. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-5621 | phpMyAdmin up to 3.1.0.0 tbl_structure.php table cross-site request forgery (EDB-7382 / Nessus ID 35089)
1 year 4 months ago
A vulnerability was found in phpMyAdmin. It has been rated as problematic. This issue affects some unknown processing of the file tbl_structure.php. The manipulation of the argument table leads to cross-site request forgery.
The identification of this vulnerability is CVE-2008-5621. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-7754 | Juniper ScreenOS 6.3.0r20 SSH Negotiation input validation (Nessus ID 87539 / ID 38652)
1 year 4 months ago
A vulnerability classified as critical has been found in Juniper ScreenOS 6.3.0r20. This affects an unknown part of the component SSH Negotiation. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2015-7754. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-7756 | Juniper ScreenOS cryptographic issues (VU#640184 / Nessus ID 87507)
1 year 4 months ago
A vulnerability was found in Juniper ScreenOS. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2015-7756. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-7768 | Konica Minolta FTP Utility 1.0 Command CWD memory corruption (Exploit 133621 / EDB-38254)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Konica Minolta FTP Utility 1.0. Affected is an unknown function of the component Command Handler. The manipulation of the argument CWD leads to memory corruption.
This vulnerability is traded as CVE-2015-7768. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-7758 | Gummi 0.6.5 link following (FEDORA-2016-94b0b50351 / Nessus ID 87629)
1 year 4 months ago
A vulnerability has been found in Gummi 0.6.5 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to link following.
This vulnerability was named CVE-2015-7758. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49044 | Microsoft Visual Studio 2022 access control
1 year 4 months ago
A vulnerability was found in Microsoft Visual Studio 2022. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-49044. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-49512 | Adobe InDesign Desktop up to 18.5.3/19.5 out-of-bounds (apsb24-88 / Nessus ID 211463)
1 year 4 months ago
A vulnerability was found in Adobe InDesign Desktop up to 18.5.3/19.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-49512. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49508 | Adobe InDesign Desktop up to 18.5.3/19.5 heap-based overflow (apsb24-88 / Nessus ID 211462)
1 year 4 months ago
A vulnerability was found in Adobe InDesign Desktop up to 18.5.3/19.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-49508. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49509 | Adobe InDesign Desktop up to 18.5.3/19.5 heap-based overflow (apsb24-88 / Nessus ID 211463)
1 year 4 months ago
A vulnerability was found in Adobe InDesign Desktop up to 18.5.3/19.5. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-49509. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-27702 | Sercomm Router Etisalat Model S3 AC2100 Diagnostic Utility access control
1 year 4 months ago
A vulnerability has been found in Sercomm Router Etisalat Model S3 AC2100 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Diagnostic Utility. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2021-27702. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com