Aggregator
喜报 | ChaMd5团队成员xyzz荣获阿里云安全守护卫士
1 year 3 months ago
RAID数据恢复深度解析:如何通过$MFT与分区结构重建Windows磁盘阵列
1 year 3 months ago
RAID数据丢失怎么办?学会分析Windows磁盘分区与文件系统,让你的RAID恢复更高效!
【偷录手机通话能作呈堂证供吗?】
1 year 3 months ago
文章原载于北京日报
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
1 year 3 months ago
In this blog entry, we discuss how the Black Basta and Cactus ransomware groups utilized the BackConnect malware to maintain persistent control and exfiltrate sensitive data from compromised machines.
Catherine Loveria
剖析Black Basta勒索软件入侵策略:泄露日志揭示的攻击手法
1 year 3 months ago
Black Basta通过暴露的RDP/VPN服务和未打补丁的系统漏洞入侵网络,依赖信息窃取软件获取凭证,迅速利用新漏洞,严重威胁企业安全。
六网合一、业务融合、云端统管——解密智慧楼宇网络建设
1 year 3 months ago
构建一体化、高效且稳健的融合通信网络体系。
CVE-2024-47883 | OpenRefine simile-butterfly up to 1.2.5 URL java.net.URL absolute path traversal (GHSA-3p8v-w8mr-m3x8)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in OpenRefine simile-butterfly up to 1.2.5. Affected by this issue is the function java.net.URL of the component URL Handler. The manipulation leads to absolute path traversal.
This vulnerability is handled as CVE-2024-47883. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47878 | OpenRefine up to 3.8.2 URL authorized state cross site scripting (GHSA-pw3x-c5vp-mfc3 / Nessus ID 215187)
1 year 3 months ago
A vulnerability was found in OpenRefine up to 3.8.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /extension/gdata/authorized of the component URL Handler. The manipulation of the argument state leads to cross site scripting.
This vulnerability is handled as CVE-2024-47878. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10374 | WP-Members Plugin up to 3.4.9.5 on WordPress Shortcode wpmem_loginout cross site scripting
1 year 3 months ago
A vulnerability was found in WP-Members Plugin up to 3.4.9.5 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function wpmem_loginout of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10374. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-47882 | OpenRefine up to 3.8.2 Exception Message cross site scripting (GHSA-j8hp-f2mj-586g / Nessus ID 215187)
1 year 3 months ago
A vulnerability classified as problematic was found in OpenRefine up to 3.8.2. This vulnerability affects unknown code of the component Exception Message Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-47882. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8666 | Shoutcast Icecast HTML5 Radio Player Plugin up to 2.1.6 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Shoutcast Icecast HTML5 Radio Player Plugin up to 2.1.6 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-8666. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10016 | WPForms File Upload Types Plugin up to 1.4.0 on WordPress SVG File Upload cross site scripting
1 year 3 months ago
A vulnerability classified as problematic has been found in WPForms File Upload Types Plugin up to 1.4.0 on WordPress. This affects an unknown part of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10016. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10112 | Simple News Plugin up to 2.8 on WordPress Shortcode cross site scripting
1 year 3 months ago
A vulnerability classified as problematic was found in Simple News Plugin up to 2.8 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-10112. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10150 | Bamazoo Plugin up to 1.0 on WordPress Shortcode cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Bamazoo Plugin up to 1.0 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10150. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2017-2469 | Apple Safari up to 10.0 WebKit memory corruption (HT207600 / EDB-41869)
1 year 3 months ago
A vulnerability was found in Apple Safari up to 10.0 and classified as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-2469. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-0465 | Apple Mac OS X 2.1.5 Installer memory corruption (EDB-29532 / Nessus ID 25081)
1 year 3 months ago
A vulnerability classified as very critical was found in Apple Mac OS X 2.1.5. This vulnerability affects unknown code of the component Installer. The manipulation leads to memory corruption.
This vulnerability was named CVE-2007-0465. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-0199 | Microsoft Internet Explorer 9/10/11 memory corruption (MS16-063 / EDB-39994)
1 year 3 months ago
A vulnerability was found in Microsoft Internet Explorer 9/10/11 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2016-0199. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-9598 | AMP for WP Plugin up to 1.0.99.1 on WordPress cross-site request forgery
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in AMP for WP Plugin up to 1.0.99.1 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-9598. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10343 | Beek Widget Extention Plugin up to 0.9.5 on WordPress Shortcode cross site scripting
1 year 3 months ago
A vulnerability has been found in Beek Widget Extention Plugin up to 0.9.5 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10343. The attack can be launched remotely. There is no exploit available.
vuldb.com