Aggregator
CVE-2009-4751 | Phppower Swinger Club Portal start.php ID sql injection (EDB-34791 / XFDB-51660)
1 month 3 weeks ago
A vulnerability was found in Phppower Swinger Club Portal. It has been rated as critical. This affects an unknown part of the file start.php. Performing a manipulation of the argument ID results in sql injection.
This vulnerability is known as CVE-2009-4751. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2009-4752 | Phppower Swinger Club Portal start.php go code injection (EDB-34792 / XFDB-51662)
1 month 3 weeks ago
A vulnerability categorized as critical has been discovered in Phppower Swinger Club Portal. This vulnerability affects unknown code of the file start.php. Executing a manipulation of the argument go can lead to code injection.
This vulnerability is handled as CVE-2009-4752. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2010-1133 | TikiWiki 4.0/4.1 sql injection (ID 12338 / XFDB-56769)
1 month 3 weeks ago
A vulnerability has been found in TikiWiki 4.0/4.1 and classified as critical. Affected by this issue is some unknown functionality. This manipulation causes sql injection.
This vulnerability is registered as CVE-2010-1133. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2010-1134 | TikiWiki up to 3.4 searchlib.php _find searchDate sql injection (ID 12338 / XFDB-56769)
1 month 3 weeks ago
A vulnerability was found in TikiWiki 3.0/3.1/3.2/3.3/3.4 and classified as critical. This affects the function _find in the library searchlib.php. Such manipulation of the argument searchDate leads to sql injection.
This vulnerability is documented as CVE-2010-1134. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2010-1132 | Georg Greve SpamAssassin Milter Plugin 0.3.1 spamass-milter.cpp mlfi_envrcpt os command injection (EDB-11662 / Nessus ID 45134)
1 month 3 weeks ago
A vulnerability, which was classified as critical, was found in Georg Greve SpamAssassin Milter Plugin 0.3.1. Affected by this vulnerability is the function mlfi_envrcpt of the file spamass-milter.cpp. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2010-1132. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-1125 | Mozilla SeaMonkey up to 2.0a1pre information disclosure (Bug 552255 / Nessus ID 47788)
1 month 3 weeks ago
A vulnerability identified as critical has been detected in Mozilla SeaMonkey. This issue affects some unknown processing. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2010-1125. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2010-1126 | Apple WebKit information disclosure (Bug 552255 / Nessus ID 53764)
1 month 3 weeks ago
A vulnerability labeled as problematic has been found in Apple WebKit. Impacted is an unknown function. The manipulation results in information disclosure.
This vulnerability was named CVE-2010-1126. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2010-1127 | Microsoft Internet Explorer 6.00.2800.1106 null pointer dereference (ID 902151)
1 month 3 weeks ago
A vulnerability marked as problematic has been reported in Microsoft Internet Explorer 6.00.2800.1106. The affected element is an unknown function. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2010-1127. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2010-1128 | PHP up to 5.2.12 uniqid cryptographic issue (EDB-33677 / Nessus ID 45029)
1 month 3 weeks ago
A vulnerability described as problematic has been identified in PHP up to 5.2.12. The impacted element is the function uniqid. Such manipulation leads to cryptographic issues.
This vulnerability is referenced as CVE-2010-1128. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2010-1129 | PHP up to 5.2.12 Access Restriction tempnam input validation (Nessus ID 56459 / ID 118433)
1 month 3 weeks ago
A vulnerability classified as critical has been found in PHP up to 5.2.12. This affects the function tempnam of the component Access Restriction. Performing a manipulation results in improper input validation.
This vulnerability is identified as CVE-2010-1129. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-1130 | PHP up to 5.3.1 Session Extension session.c session_save_path access control (EDB-33625 / Nessus ID 56459)
1 month 3 weeks ago
A vulnerability classified as critical was found in PHP. This impacts the function session_save_path of the file session.c of the component Session Extension. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2010-1130. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
vuldb.com
CVE-2010-1131 | Apple Safari 4.0.5 JavaScriptCore.dll denial of service (EDB-12487 / ID 117120)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Apple Safari 4.0.5. Affected is an unknown function in the library JavaScriptCore.dll. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2010-1131. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers
1 month 3 weeks ago
PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers
The post PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers appeared first on Security Boulevard.
Tom Abai
PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers
1 month 3 weeks ago
The post PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, an
1,5 миллиона серверов, один эксплойт, полный контроль. Как вымогатели захватывают сайты через cPanel
1 month 3 weeks ago
Владельцы буквально оказались в ловушке между хакерами и хостерами.
CVE-2009-4750 | Phppower Top Paidmailer home.php page code injection (EDB-34793 / XFDB-51661)
1 month 3 weeks ago
A vulnerability was found in Phppower Top Paidmailer. It has been declared as critical. Affected by this issue is some unknown functionality of the file home.php. Such manipulation of the argument page leads to code injection.
This vulnerability is traded as CVE-2009-4750. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-4743 | AfterLogic WebMail Pro up to 4.5 history-storage.aspx cross site scripting (EDB-9857 / XFDB-53672)
1 month 3 weeks ago
A vulnerability classified as problematic has been found in AfterLogic WebMail Pro up to 4.5. Impacted is an unknown function of the file history-storage.aspx. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2009-4743. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2009-4744 | Oicgroup CMS 0.97-ga20090213 email cross site scripting (XFDB-53687 / BID-36626)
1 month 3 weeks ago
A vulnerability classified as problematic was found in Oicgroup CMS 0.97-ga20090213. The affected element is an unknown function. Such manipulation of the argument email leads to cross site scripting.
This vulnerability is listed as CVE-2009-4744. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2009-4740 | TYPO3 Ws Ecard up to 1.0.2 path traversal
1 month 3 weeks ago
A vulnerability labeled as problematic has been found in TYPO3 Ws Ecard up to 1.0.2. This affects an unknown part. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2009-4740. The attack may be launched remotely. There is no exploit available.
vuldb.com