Aggregator
Randall Munroe’s XKCD ‘Disposal’
1 year 5 months ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Disposal’ appeared first on Security Boulevard.
Marc Handelman
CVE-2024-48336 | Magisk App prior 27007 ProviderInstaller.java install Local Privilege Escalation
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Magisk App. This affects the function install of the file ProviderInstaller.java. The manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-48336. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #437018: code-projects E-Health Care System IN PHP v1.0 Easy SQL Injection [Accepted]
1 year 5 months ago
Submit #437018 / VDB-283038
moonose
Submit #436759: code-projects E-Health Care System IN PHP v1.0 SQL INJECTION [Accepted]
1 year 5 months ago
Submit #436759 / VDB-283037
Xueweian
Submit #436566: code-projects E-Health Care System IN PHP v1.0 SQL INJECTION [Accepted]
1 year 5 months ago
Submit #436566 / VDB-283036
Koevas
CVE-2024-51326 | projectworlds Travel Management System 1.0 deletesubcategory.php deletesubcategory t2 sql injection
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in projectworlds Travel Management System 1.0. Affected by this issue is the function deletesubcategory of the file deletesubcategory.php. The manipulation of the argument t2 leads to sql injection.
This vulnerability is handled as CVE-2024-51326. The attack may be launched remotely. There is no exploit available.
vuldb.com
更新3节:动态分析 | 看雪安卓高级研修班(月薪一万计划)
1 year 5 months ago
一起探索安卓逆向的奥秘
近100万台存在高危漏洞的 Fortinet、SonicWall 设备正暴露在公开网络中
1 year 5 months ago
SDC2024 议题回顾 | 从硬件钱包到TrustZone:Web3密钥托管的安全挑战与解决方案
1 year 5 months ago
剖析真实漏洞案例,融合开源方案实践
CVE-2024-51328 | projectworlds Travel Management System 1.0 addcategory.php t2 cross site scripting
1 year 5 months ago
A vulnerability classified as problematic was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file addcategory.php. The manipulation of the argument t2 leads to cross site scripting.
This vulnerability is known as CVE-2024-51328. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51327 | projectworlds Travel Management System 1.0 loginform.php username/password sql injection
1 year 5 months ago
A vulnerability classified as critical has been found in projectworlds Travel Management System 1.0. Affected is an unknown function of the file loginform.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is traded as CVE-2024-51327. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
六年来首次停滞!网络安全就业市场提前入冬
1 year 5 months ago
德国大型药品批发商遭勒索攻击,欲扰乱超6000家药房供应
1 year 5 months ago
只能向药店提供有限范围的供货
BlockFramework —— 客户端模块化业务开发框架
1 year 5 months ago
良好架构是大型APP共同开发的支撑。BlockFramework是西瓜视频团队研发的一套客户端业务开发框架,具备业务分层、组装以及协同的能力,业务方基于此框架能够轻易实现业务解耦,独立开展逻辑迭代,从而提升架构的稳定性。
CVE-2024-10807 | PHPGurukul Hospital Management System 4.0 hms/doctor/search.php searchdata cross site scripting
1 year 5 months ago
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10807. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10806 | PHPGurukul Hospital Management System 4.0 betweendates-detailsreports.php fromdate/todate cross site scripting
1 year 5 months ago
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting.
This vulnerability was named CVE-2024-10806. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Custom "Pygmy Goat" malware used in Sophos Firewall hack on govt network
1 year 5 months ago
UK's National Cyber Security Centre (NCSC) has published an analysis of a Linux malware named "Pigmy Goat" created to backdoor Sophos XG firewall devices as part of recently disclosed attacks by Chinese threat actors. [...]
Bill Toulas
CVE-2024-10805 | code-projects University Event Management System 1.0 doedit.php id sql injection
1 year 5 months ago
A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file doedit.php. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10805. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The initial researcher advisory mentions a confusing product name to be affected. Other parameters might be affected as well.
vuldb.com
Submit #436551: PHPGurukul Hospital Management System (HMS) 4.0 Improper Neutralization of Alternate XSS Syntax [Accepted]
1 year 5 months ago
Submit #436551 / VDB-283031
secuserx