Aggregator
.NET 安全攻防知识交流社区
1 year 5 months ago
.NET内网实战:通过白名单文件反序列化漏洞绕过UAC
1 year 5 months ago
CVE-2024-10193 | WAVLINK WN530H4/WN530HG4/WN572HG3 up to 20221028 internet.cgi ping_ddns DDNS command injection
1 year 5 months ago
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_ddns of the file internet.cgi. The manipulation of the argument DDNS leads to command injection.
The identification of this vulnerability is CVE-2024-10193. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10194 | WAVLINK WN530H4/WN530HG4/WN572HG3 up to 20221028 Front-End Authentication Page login.cgi Goto_chidx wlanUrl stack-based overflow
1 year 5 months ago
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been classified as critical. Affected is the function Goto_chidx of the file login.cgi of the component Front-End Authentication Page. The manipulation of the argument wlanUrl leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-10194. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
It is recommended to apply restrictive firewalling.
vuldb.com
OpenAI 前 CTO 创业,要融资 1 亿美元;张艺谋为《三体》电影成立 AI 小组;传科学家复活死亡猪脑 | 极客早知道
1 year 5 months ago
英伟达力挺特斯拉人形机器人:远程操控也很先进;大疆起诉美国国防部;Meta 发布新模型:用AI 评估 AI 能力。
CVE-2008-0069 | Pierreegougelet XnView 1.92/1.92.1 FontName memory corruption (EDB-5346 / XFDB-41542)
1 year 5 months ago
A vulnerability has been found in Pierreegougelet XnView 1.92/1.92.1 and classified as critical. This vulnerability affects unknown code. The manipulation of the argument FontName leads to memory corruption.
This vulnerability was named CVE-2008-0069. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1696 | DaZPHP DaZPHPNews 0.1-1 makepost.php prefixdir path traversal (EDB-5347 / XFDB-41608)
1 year 5 months ago
A vulnerability was found in DaZPHP DaZPHPNews 0.1-1. It has been rated as problematic. This issue affects some unknown processing of the file makepost.php. The manipulation of the argument prefixdir leads to path traversal.
The identification of this vulnerability is CVE-2008-1696. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1776 | PhpBlock A8.4 PATH_TO_CODE code injection (EDB-5348 / XFDB-41616)
1 year 5 months ago
A vulnerability classified as critical has been found in PhpBlock A8.4. This affects an unknown part. The manipulation of the argument PATH_TO_CODE leads to code injection.
This vulnerability is uniquely identified as CVE-2008-1776. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1682 | Elearningforce Online FlashQuiz 1.0.2 base_dir code injection (EDB-5345 / XFDB-41592)
1 year 5 months ago
A vulnerability was found in Elearningforce Online FlashQuiz 1.0.2 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument base_dir leads to code injection.
This vulnerability is handled as CVE-2008-1682. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1855 | McAfee CMA 3.6.0.574 Management Agent frameworkservice.exe resource management (EDB-5343 / Nessus ID 42871)
1 year 5 months ago
A vulnerability was found in McAfee CMA 3.6.0.574 and classified as problematic. Affected by this issue is some unknown functionality of the file frameworkservice.exe of the component Management Agent. The manipulation leads to improper resource management.
This vulnerability is handled as CVE-2008-1855. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-1697 | HP OpenView Network Node Manager up to 7.0.1 ovas.exe memory corruption (EDB-5342 / Nessus ID 39380)
1 year 5 months ago
A vulnerability classified as very critical has been found in HP OpenView Network Node Manager up to 7.0.1. Affected is an unknown function in the library ovwparser.dll of the file ovas.exe of the component Node Manager. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2008-1697. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1713 | NoticeWare Email Server 4.6.1.0 mailserver.exe denial of service (EDB-5341 / XFDB-41581)
1 year 5 months ago
A vulnerability was found in NoticeWare Email Server 4.6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file mailserver.exe. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2008-1713. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Week in review: 87k+ Fortinet devices still open to attack, red teaming tool used for EDR evasion
1 year 5 months ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 87,000+ Fortinet devices still open to attack, are yours among them? (CVE-2024-23113) Last week, CISA added CVE-2024-23113 – a critical vulnerability that allows unauthenticated remote code/command execution on unpatched Fortinet FortiGate firewalls – to its Known Exploited Vulnerabilities catalog, thus confirming that it’s being leveraged by attackers in the wild. Attackers deploying red teaming tool for EDR evasion Threat actors … More →
The post Week in review: 87k+ Fortinet devices still open to attack, red teaming tool used for EDR evasion appeared first on Help Net Security.
Help Net Security
CVE-2014-5704 | DISH DISH Anywhere 3.5.10 X.509 Certificate cryptographic issues (ID 131271 / VU#582497)
1 year 5 months ago
A vulnerability was found in DISH DISH Anywhere 3.5.10 and classified as critical. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-5704. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
Erstellung und Nutzung von Transkription und LLMs für Podcasts (subscribe11)
1 year 5 months ago
Was war Samstag? (subscribe11)
1 year 5 months ago
Src实战案例分享
1 year 5 months ago
No.0前言挖洞就是要多思考,要是没有权限我们需要如何突破限制进行测试,我是No.2案例一首先登录XXXX平台然后找到以下接口。GET /user/credit?company=111111 HTTP
CVE-2008-1647 | Chilkat Software ChilkatHttp ActiveX up to 2.3.0.0 ActiveX Control chilkathttp.dll input validation (EDB-5338 / XFDB-45988)
1 year 5 months ago
A vulnerability was found in Chilkat Software ChilkatHttp ActiveX up to 2.3.0.0 and classified as very critical. Affected by this issue is some unknown functionality in the library chilkathttp.dll of the component ActiveX Control. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2008-1647. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1650 | Myiosoft EasyNews 4.0tr Help read sql injection (EDB-5333 / XFDB-41590)
1 year 5 months ago
A vulnerability was found in Myiosoft EasyNews 4.0tr. It has been rated as critical. This issue affects some unknown processing of the component Help. The manipulation of the argument read leads to sql injection.
The identification of this vulnerability is CVE-2008-1650. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com