Aggregator
Mazda Connect flaws allow to hack some Mazda vehicles
10 months ago
Multiple vulnerabilities in the infotainment unit Mazda Connect could allow attackers to execute arbitrary code with root access. Trend Micro’s Zero Day Initiative warned of multiple vulnerabilities in the Mazda Connect infotainment system that could allow attackers to execute code with root privileges. This occurs due to improper input sanitization in the Mazda Connect CMU, […]
Pierluigi Paganini
CVE-2022-34140 | Feehi CMS 2.1.1 index.php?r=site%2Fsignup username cross site scripting (Issue 61 / EDB-51018)
10 months ago
A vulnerability classified as problematic was found in Feehi CMS 2.1.1. Affected by this vulnerability is an unknown functionality of the file /index.php?r=site%2Fsignup. The manipulation of the argument username leads to cross site scripting.
This vulnerability is known as CVE-2022-34140. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
BianLian
10 months ago
cohenido
CVE-2015-8411 | Adobe Flash Player up to 11.2.202.548/18.0.0.261/19.0.0.245 use after free (APSB15-32 / EDB-39041)
10 months ago
A vulnerability was found in Adobe Flash Player up to 11.2.202.548/18.0.0.261/19.0.0.245. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to use after free.
This vulnerability was named CVE-2015-8411. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Metared Argentina CERTUNLP
10 months ago
Name: Metared Argentina CERTUNLP (an CTF Internacional MetaRed event.)
Date: Nov. 8, 2024, 11 a.m. — 09 Nov. 2024, 11:00 UTC [add to calendar]
Format: Jeopardy
On-line
Location: https://ctf.cert.unlp.edu.ar
Offical URL: https://ctf.cert.unlp.edu.ar/
Rating weight: 25.00
Event organizers: CERTUNLP
Date: Nov. 8, 2024, 11 a.m. — 09 Nov. 2024, 11:00 UTC [add to calendar]
Format: Jeopardy
On-line
Location: https://ctf.cert.unlp.edu.ar
Offical URL: https://ctf.cert.unlp.edu.ar/
Rating weight: 25.00
Event organizers: CERTUNLP
Bambi CTF #11
10 months ago
Name: Bambi CTF #11 (an Bambi CTF event.)
Date: Nov. 9, 2024, 11 a.m. — 09 Nov. 2024, 17:00 UTC [add to calendar]
Format: Attack-Defense
On-line
Offical URL: https://bambi11.enoflag.de/
Rating weight: 85.71
Event organizers: ENOFLAG
Date: Nov. 9, 2024, 11 a.m. — 09 Nov. 2024, 17:00 UTC [add to calendar]
Format: Attack-Defense
On-line
Offical URL: https://bambi11.enoflag.de/
Rating weight: 85.71
Event organizers: ENOFLAG
通过发现隐藏的参数值实现任意用户登录
10 months ago
CVE-1999-1008 | FreeBSD/Linux xsoldier Long Argument memory corruption (EDB-229 / XFDB-3925)
10 months ago
A vulnerability, which was classified as critical, was found in FreeBSD and Linux. Affected is an unknown function of the component xsoldier. The manipulation as part of Long Argument leads to memory corruption.
This vulnerability is traded as CVE-1999-1008. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Google says “Enhanced protection” feature in Chrome now uses AI
10 months ago
Google has quietly updated the description of one of the Chrome's security features "Enhanced protection" to confirm that it will be powered by AI in a future release. [...]
Mayank Parmar
CVE-2008-6242 | Scripts-for-Sites EZ e-store SearchResults.php where sql injection (EDB-6922 / XFDB-46273)
10 months ago
A vulnerability, which was classified as critical, was found in Scripts-for-Sites EZ e-store. This affects an unknown part of the file SearchResults.php. The manipulation of the argument where leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-6242. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6778 | Scripts-for-Sites EZ Auction viewfaqs.php cat sql injection (EDB-6918 / XFDB-46276)
10 months ago
A vulnerability has been found in Scripts-for-Sites EZ Auction and classified as critical. This vulnerability affects unknown code of the file viewfaqs.php. The manipulation of the argument cat leads to sql injection.
This vulnerability was named CVE-2008-6778. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6867 | Scripts For Sites EZ Career content.php topic sql injection (EDB-6919 / XFDB-46275)
10 months ago
A vulnerability, which was classified as critical, was found in Scripts For Sites EZ Career. This affects an unknown part of the file content.php. The manipulation of the argument topic leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-6867. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-4902 | Scripts Frenzy Article Publisher Pro 1.5 contact_author.php userid sql injection (EDB-6917 / XFDB-46266)
10 months ago
A vulnerability, which was classified as critical, was found in Scripts Frenzy Article Publisher Pro 1.5. This affects an unknown part of the file contact_author.php. The manipulation of the argument userid leads to sql injection.
This vulnerability is uniquely identified as CVE-2008-4902. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6247 | Scripts-for-Sites EZ Top Sites topsite.php ts sql injection (EDB-6920 / XFDB-46274)
10 months ago
A vulnerability was found in Scripts-for-Sites EZ Top Sites. It has been rated as critical. Affected by this issue is some unknown functionality of the file topsite.php. The manipulation of the argument ts leads to sql injection.
This vulnerability is handled as CVE-2008-6247. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Scammers target UK senior citizens with Winter Fuel Payment texts
10 months ago
As the winter season kicks in, scammers are not missing the chance to target senior British residents with bogus "winter heating allowance" and "cost of living support" scam texts. [...]
Ax Sharma
CVE-2019-13990 | Oracle Retail Order Broker 15.0/16.0/18.0/19.0 Order Broker Foundation xml external entity reference (Nessus ID 210560)
10 months ago
A vulnerability was found in Oracle Retail Order Broker 15.0/16.0/18.0/19.0. It has been classified as very critical. This affects an unknown part of the component Order Broker Foundation. The manipulation leads to xml external entity reference.
This vulnerability is uniquely identified as CVE-2019-13990. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle Retail Point-of-Service 14.1 Security xml external entity reference (Nessus ID 210560)
10 months ago
A vulnerability was found in Oracle Retail Point-of-Service 14.1. It has been declared as very critical. This vulnerability affects unknown code of the component Security. The manipulation leads to xml external entity reference.
This vulnerability was named CVE-2019-13990. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle Retail Returns Management 14.1 Security xml external entity reference (Nessus ID 210560)
10 months ago
A vulnerability classified as very critical has been found in Oracle Retail Returns Management 14.1. Affected is an unknown function of the component Security. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2019-13990. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle Fusion Middleware MapViewer 12.2.1.3.0 Install xml external entity reference (Nessus ID 210560)
10 months ago
A vulnerability, which was classified as very critical, was found in Oracle Fusion Middleware MapViewer 12.2.1.3.0. This affects an unknown part of the component Install. The manipulation leads to xml external entity reference.
This vulnerability is uniquely identified as CVE-2019-13990. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com