Aggregator
The HackerNoon Newsletter: The Clever Programmer (11/10/2024)
10 months ago
ByteAI安全挑战赛-ChaMd5团队总结报告
10 months ago
数据安全事件怎么分级,怎么上报?官方模板速取
10 months ago
加快构建数据安全事件应急管理体系,提升事件处置水平。
威努特工业交换机,筑牢特种玻璃智能制造行业生产基石
10 months ago
建设安全可靠的工控系统网络,提升生产效率和质量控制能力。
Trend Micro and Japanese Partners Reveal Hidden Connections Among SEO Malware Operations
10 months ago
Trend Micro researchers, in collaboration with Japanese authorities, analyzed links between SEO malware families used in SEO poisoning attacks that lead users to fake shopping sites.
Makoto Shimamura
DEF CON 32 – SQL Injection Isn’t Dead Smuggling Queries at the Protocol Level
10 months ago
Sunday, November 10, 2024
CVE-2012-2953 | Symantec Web Gateway up to 5.0.3.18 spywall/pbcontrol.php filename os command injection (SYM12-011 / EDB-20088)
10 months ago
A vulnerability, which was classified as critical, has been found in Symantec Web Gateway up to 5.0.3.18. This issue affects some unknown processing of the file spywall/pbcontrol.php. The manipulation of the argument filename leads to os command injection.
The identification of this vulnerability is CVE-2012-2953. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Windows 11 is adding a 'Share' button to the Start menu and Taskbar
10 months ago
Microsoft wants you to share content/items more frequently, so it's now adding the "Share" button everywhere, including the Start menu and even the taskbar. [...]
Mayank Parmar
zipdump & PKZIP Records, (Sun, Nov 10th)
10 months ago
In yesterday's diary entry "zipdump & Evasive ZIP Concatenation" I showed how one can inspect the P
CVE-2008-6252 | smcFanControl 2.1.2 main memory corruption (EDB-7088 / XFDB-46551)
10 months ago
A vulnerability was found in smcFanControl 2.1.2. It has been classified as critical. This affects the function main. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2008-6252. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6965 | AJ Square AJ Auction 2.0 site.php improper authentication (EDB-7087 / XFDB-46528)
10 months ago
A vulnerability, which was classified as critical, was found in AJ Square AJ Auction 2.0. Affected is an unknown function of the file site.php. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2008-6965. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6966 | AJ Square AJ Auction 1.0 access control (EDB-7087 / XFDB-46528)
10 months ago
A vulnerability has been found in AJ Square AJ Auction 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2008-6966. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6930 | PHPStore Real Estate File Upload access control (EDB-7085 / XFDB-52446)
10 months ago
A vulnerability was found in PHPStore Real Estate. It has been rated as critical. This issue affects some unknown processing of the component File Upload. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2008-6930. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-7045 | Ajsquare Free Polling Script improper authentication (EDB-7086 / SA32600)
10 months ago
A vulnerability classified as critical was found in Ajsquare Free Polling Script. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2008-7045. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-7044 | Ajsquare Free Polling Script ques sql injection (EDB-7086 / XFDB-46530)
10 months ago
A vulnerability classified as critical has been found in Ajsquare Free Polling Script. Affected is an unknown function. The manipulation of the argument ques leads to sql injection.
This vulnerability is traded as CVE-2008-7044. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
一次通过Fuzz API发现漏洞的旅程
10 months ago
由于漏洞披露原因,暂将目标网站称为“target.com”。在对目标网站进行漏洞挖掘时,首先的一些必要动作包括:重置电子邮件获取密码尝试登录,发现是否存在一些逻辑漏洞在Burp中选择Target ->
CVE-2010-2939 | OpenSSL 0.9.7/0.9.8/1.0.0a ssl3_get_key_exchange resource management (USN-1003-1 / EDB-34427)
10 months ago
A vulnerability classified as critical has been found in OpenSSL 0.9.7/0.9.8/1.0.0a. This affects the function ssl3_get_key_exchange. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2010-2939. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Reversing the Parrot Anafi drone and start/land it using a PC
10 months ago
CVE-2008-6928 | PHPStore Complete Classifieds File Upload access control (EDB-7084 / SA32626)
10 months ago
A vulnerability was found in PHPStore Complete Classifieds. It has been classified as critical. This affects an unknown part of the component File Upload. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2008-6928. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com