Aggregator
CVE-2018-8716 | WSO2 Identity Server up to 5.4.x Dashboard cross site scripting (ID 147330 / EDB-44531)
1 year 4 months ago
A vulnerability has been found in WSO2 Identity Server up to 5.4.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Dashboard. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2018-8716. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Chort
1 year 4 months ago
cohenido
Chort
1 year 4 months ago
cohenido
Chort
1 year 4 months ago
cohenido
Chort
1 year 4 months ago
cohenido
Chort
1 year 4 months ago
cohenido
Black Suit
1 year 4 months ago
cohenido
Black Suit
1 year 4 months ago
cohenido
RansomHub
1 year 4 months ago
cohenido
CVE-2024-4577 RCE Exploit; PHP CGI Argument Injection
1 year 4 months ago
CVE-2024-4577 RCE Exploit; PHP CGI Argument Injection
Dark Web Informer
RansomHub
1 year 4 months ago
cohenido
DEF CON 32 – Manipulating Shim And Office For Code Injection
1 year 4 months ago
Authors/Presenters: Ron Ben-Yizhak, David Shandalov
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Manipulating Shim And Office For Code Injection appeared first on Security Boulevard.
Marc Handelman
Botnet exploits GeoVision zero-day to install Mirai malware
1 year 4 months ago
A malware botnet is exploiting a zero-day vulnerability in end-of-life GeoVision devices to compromise and recruit them for likely DDoS or cryptomining attacks. [...]
Bill Toulas
CVE-2008-6535 | Paypalestores PayPal eStores Access Restriction admin/settings.php NewAdmin access control (EDB-7367 / XFDB-47203)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Paypalestores PayPal eStores. Affected is an unknown function of the file admin/settings.php of the component Access Restriction. The manipulation of the argument NewAdmin leads to improper access controls.
This vulnerability is traded as CVE-2008-6535. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5565 | Dinkumsoft DL PayCart up to 1.34 cross-site request forgery (EDB-7365 / SA33038)
1 year 4 months ago
A vulnerability classified as critical has been found in Dinkumsoft DL PayCart up to 1.34. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2008-5565. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5567 | Bonzacart Bonza Cart up to 1.10 cross-site request forgery (EDB-7366 / SA33037)
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Bonzacart Bonza Cart up to 1.10. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2008-5567. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5568 | Ipn-mate IPN Pro 3 up to 1.44 cross-site request forgery (EDB-7364 / SA33039)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Ipn-mate IPN Pro 3 up to 1.44. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2008-5568. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5587 | phpPgAdmin up to 4.2.1 Libraries libraries/lib.inc.php _language path traversal (EDB-7363 / Nessus ID 74596)
1 year 4 months ago
A vulnerability has been found in phpPgAdmin up to 4.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality in the library libraries/lib.inc.php of the component Libraries. The manipulation of the argument _language leads to path traversal.
This vulnerability is known as CVE-2008-5587. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
A Threat Actor is Allegedly Selling Access to an Unidentified Energy Company in South America
1 year 4 months ago
A Threat Actor is Allegedly Selling Access to an Unidentified Energy Company in South America
Dark Web Informer