Aggregator
.NET内网实战:反射实现Rundll32绕过防护
8 months ago
.NET内网实战:反射实现Rundll32绕过防护
8 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
.NET 2024.12月度红队武器库和资源汇总
8 months ago
01阅读须知此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直
.NET 安全攻防知识交流社区
8 months ago
01欢迎加入社区为了更好地应对基于.NET技术栈的风险识别和未知威胁,dotNet安全矩阵星球从创建以来一直聚焦于.NET领域的安全攻防技术,定位于高质量安全攻防星球社区,也得到了许多师傅们的支持和信
CVE-2008-1985 | Digital Hive DigitalHive 2.0 base.php mt cross site scripting (EDB-10427 / XFDB-42006)
8 months ago
A vulnerability, which was classified as problematic, has been found in Digital Hive DigitalHive 2.0. Affected by this issue is some unknown functionality of the file base.php. The manipulation of the argument mt leads to cross site scripting.
This vulnerability is handled as CVE-2008-1985. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
马斯克称Grok3即将发布;泄漏领克900车型,自媒体被索赔500万元;小米汽车工厂已开放对外参观预约 | 极客早知道
8 months ago
阿里发布 Qwen-Agent 框架,赋能开发者构建复杂 AI 智能体;Anthropic 让步:Claude AI 不再生成受版权保护的歌词;比亚迪发布汉 / 唐 L 设计图
马斯克称Grok3即将发布;泄漏领克900车型,自媒体被索赔500万元;小米汽车工厂已开放对外参观预约 | 极客早知道
8 months ago
全球航天新年首飞,SpaceX 发射阿联酋卫星北京时间 1 月 4 日晨,猎鹰 9 号火箭从卡纳维拉尔角太空军基地发射升空,将阿联酋通信卫星 Thuraya 4-NGS 送入轨道。起飞 8 分 40
CVE-2004-2286 | Activestate Activeperl up to 5.8.3 integer coercion (EDB-24130 / XFDB-16224)
8 months ago
A vulnerability has been found in Activestate Activeperl up to 5.8.3 and classified as critical. This vulnerability affects unknown code. The manipulation leads to integer coercion error.
This vulnerability was named CVE-2004-2286. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Apple Settles 'Hey Siri' Lawsuit for $95 Million
8 months ago
Plaintiffs Sued After Report that Apple Eavesdropped on Intimate Moments
Apple agreed to pay $95 million to settle a lawsuit accusing the smart device giant of illegally recording audio through its Siri virtual assistant and sharing extracts with human reviewers. Class members who purchased Siri-enabled devices could receive $20 per device.
Apple agreed to pay $95 million to settle a lawsuit accusing the smart device giant of illegally recording audio through its Siri virtual assistant and sharing extracts with human reviewers. Class members who purchased Siri-enabled devices could receive $20 per device.
Apple Settles 'Hey Siri' Lawsuit for $95 Million
8 months ago
Plaintiffs Sued After Report that Apple Eavesdropped on Intimate Moments
Apple agreed to pay $95 million to settle a lawsuit accusing the smart device giant of illegally recording audio through its Siri virtual assistant and sharing extracts with human reviewers. Class members who purchased Siri-enabled devices could receive $20 per device.
Apple agreed to pay $95 million to settle a lawsuit accusing the smart device giant of illegally recording audio through its Siri virtual assistant and sharing extracts with human reviewers. Class members who purchased Siri-enabled devices could receive $20 per device.
CVE-2006-2370 | Microsoft Windows 2000/Server 2003/XP Routing/Remote Access Service RPC Request memory corruption (MS06-025 / VU#631516)
8 months ago
A vulnerability was found in Microsoft Windows 2000/Server 2003/XP and classified as critical. This issue affects some unknown processing of the component Routing/Remote Access Service. The manipulation as part of RPC Request leads to memory corruption.
The identification of this vulnerability is CVE-2006-2370. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-1388 | Microsoft Internet Explorer up to 6 HTA memory corruption (MS06-013 / VU#434641)
8 months ago
A vulnerability has been found in Microsoft Internet Explorer up to 6 and classified as critical. This vulnerability affects unknown code of the component HTA Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2006-1388. The attack can be initiated remotely. There is no exploit available.
It is recommended to replace the affected component with an alternative.
vuldb.com
CVE-2006-1316 | Microsoft Office code injection (MS06-038 / VU#580036)
8 months ago
A vulnerability was found in Microsoft Office. It has been classified as critical. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2006-1316. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2006-1316 | Microsoft Office 2000/2003/XP Document String code injection (MS06-038 / VU#580036)
8 months ago
A vulnerability classified as critical has been found in Microsoft Office 2000/2003/XP. This affects an unknown part of the component Document String Handler. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2006-1316. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2018-4328 | Apple iTunes up to 12.8 on Windows memory corruption (EDB-45483 / Nessus ID 119323)
8 months ago
A vulnerability was found in Apple iTunes up to 12.8 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2018-4328. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-2924 | Hypermethod eLearning Server 4g path code injection (EDB-18858 / XFDB-75514)
8 months ago
A vulnerability was found in Hypermethod eLearning Server 4g and classified as critical. This issue affects some unknown processing. The manipulation of the argument path leads to code injection.
The identification of this vulnerability is CVE-2012-2924. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6210 | Zabbix up to 1.1.2 zabbix_agentd config (EDB-30839 / Nessus ID 29272)
8 months ago
A vulnerability was found in Zabbix up to 1.1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component zabbix_agentd. The manipulation leads to configuration.
This vulnerability is known as CVE-2007-6210. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2002-1058 | Cobalt Qube 3.0 Admin splashAdmin.php path traversal (EDB-21640 / XFDB-9669)
8 months ago
A vulnerability was found in Cobalt Qube 3.0. It has been rated as critical. This issue affects some unknown processing of the file splashAdmin.php of the component Admin. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2002-1058. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
It is possible to hack an online game from Android?
8 months ago