Aggregator
CVE-2008-5123 | Castillocentral CCleague 1.2 admin.php sql injection (EDB-5888 / XFDB-43280)
CVE-2008-5125 | Castillocentral CCleague 1.2 admin.php improper authentication (EDB-5888 / XFDB-43281)
CVE-2008-2833 | Worldlevel le.cms 1.4 submit0 improper authentication (EDB-5887 / XFDB-43274)
CVE-2008-2834 | Sidb Scientific Image DataBase 0.41 projects.php id sql injection (EDB-5885 / XFDB-43255)
CVE-2010-4254 | Novell Moonlight up to 2.99.9 input validation (EDB-15974 / Nessus ID 75587)
От защиты до уязвимости: App-Bound Encryption в Chrome оказался не так крепок
CVE-2010-1677 | MHonArc 2.6.16 resource management (EDB-35478 / Nessus ID 52727)
SMB Force-Authentication Vulnerability Impacts All OPA Versions For Windows
Open Policy Agent (OPA) recently patched a critical vulnerability that could have exposed NTLM credentials of the OPA server’s local user account to remote attackers, which was present in both the OPA CLI and Go SDK. By exploiting this flaw, attackers could have compromised the OPA server’s authentication mechanisms and potentially gained unauthorized access to […]
The post SMB Force-Authentication Vulnerability Impacts All OPA Versions For Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Latrodectus Employs New anti-Debugging And Sandbox Evasion Techniques
Latrodectus, a new malware loader, has rapidly evolved since its discovery, potentially replacing IcedID. It includes a command to download IcedID and has undergone multiple iterations, likely to evade detection. Extracting configurations from these versions is crucial for effective threat detection, as the Latrodectus malware has evolved over the past year, with new versions released […]
The post Latrodectus Employs New anti-Debugging And Sandbox Evasion Techniques appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-50481 | Stack Themes Bstone Demo Importer Plugin up to 1.0.1 on WordPress privileges assignment
CVE-2024-50426 | Survey Maker Plugin up to 5.0.2 on WordPress cross site scripting
CVE-2024-46872 | Mattermost up to 9.5.9/9.10.2/9.11.1 Playbook cross-site request forgery
CVE-2024-50420 | aDirectory Plugin up to 1.3 on WordPress unrestricted upload
CVE-2024-50476 | Grün Spendino Spendenformular Plugin up to 1.0.1 on WordPress authorization
CVE-2024-10241 | Mattermost up to 9.5.9 Channel Name access control
CVE-2024-50418 | Time Slot Booking Time Slot Plugin up to 1.3.6 on WordPress cross site scripting
CVE-2024-50473 | Ajar in5 Embed Plugin up to 3.1.3 on WordPress unrestricted upload
Hardcoded Creds in Popular Apps Put Millions of Android and iOS Users at Risk
Recent analysis has revealed a concerning trend in mobile app security: Many popular apps store hardcoded and unencrypted cloud service credentials directly within their codebases. It poses a significant security risk as anyone accessing the app’s binary or source code could extract and misuse these credentials to manipulate or exfiltrate data. Examples include Pic Stitch, […]
The post Hardcoded Creds in Popular Apps Put Millions of Android and iOS Users at Risk appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.