Aggregator
CVE-2023-33653 | Sitecore Experience Platform 9.3 Execute.aspx?cmd=convert&mode=HTML Privilege Escalation
1 year 3 months ago
A vulnerability classified as critical was found in Sitecore Experience Platform 9.3. This vulnerability affects unknown code of the file /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2023-33653. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-29632 | jmspagebuilder 3.x on PrestaShop ajax_jmspagebuilder.php sql injection
1 year 3 months ago
A vulnerability, which was classified as critical, was found in jmspagebuilder 3.x on PrestaShop. This affects an unknown part of the file ajax_jmspagebuilder.php. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-29632. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-34409 | Percona Monitoring and Management Server up to 2.37.0 POST auth_server.go path traversal
1 year 3 months ago
A vulnerability has been found in Percona Monitoring and Management Server up to 2.37.0 and classified as critical. This vulnerability affects unknown code of the file auth_server.go of the component POST Handler. The manipulation leads to path traversal.
This vulnerability was named CVE-2023-34409. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33651 | Sitecore Experience Platform MVC Device Simulator improper authorization (KB1002925)
1 year 3 months ago
A vulnerability was found in Sitecore Experience Platform, Experience Manager and Experience Commerce and classified as critical. This issue affects some unknown processing of the component MVC Device Simulator. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2023-33651. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-45878 | GibbonEdu Gibbon up to 25.0.1 rubrics_visualise_saveAjax.phps img/path/gibbonPersonID improper authentication (usd-2023-0025)
1 year 3 months ago
A vulnerability was found in GibbonEdu Gibbon up to 25.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file rubrics_visualise_saveAjax.phps. The manipulation of the argument img/path/gibbonPersonID leads to improper authentication.
This vulnerability is handled as CVE-2023-45878. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2021-46964 | Linux Kernel up to 5.11.19/5.12/5.12.2 qla2xxx qla83xx_iospace_config null pointer dereference (4ecd42dec858/0f86d66b3850/f02d4086a8f3)
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.11.19/5.12/5.12.2. This affects the function qla83xx_iospace_config of the component qla2xxx. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2021-46964. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Pall Mall Process to tackle commercial hacking proliferation raises more concerns than solutions
1 year 3 months ago
A year on from the launch of the Pall Mall Process to tackle “the proliferation and irresponsible u
Cyber Command overhaul gets Austin’s approval, but plan faces uncertain future
1 year 3 months ago
Defense Secretary Lloyd Austin last month approved a restructuring of U.S. Cyber Command, though qu
CVE-2003-1435 | Francisco Burzi PHP-Nuke 5.6/6.0 Search Module days sql injection (EDB-22266 / Nessus ID 11236)
1 year 3 months ago
A vulnerability was found in Francisco Burzi PHP-Nuke 5.6/6.0. It has been classified as critical. Affected is an unknown function of the component Search Module. The manipulation of the argument days leads to sql injection.
This vulnerability is traded as CVE-2003-1435. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
[Control systems] ABB security advisory (AV25-010)
1 year 3 months ago
Canadian Centre for Cyber Security
What Makes You… You? A Philosophical Take on Non-Human Identity
1 year 3 months ago
6 min readFrom DNA to data, explore the unanswered questions of identity and the challenges of securing a non-human world.
The post What Makes You… You? A Philosophical Take on Non-Human Identity appeared first on Aembit.
The post What Makes You… You? A Philosophical Take on Non-Human Identity appeared first on Security Boulevard.
Victor Ronin
DEF CON 32 – Student Engagement Doesn’t Have to Suck
1 year 3 months ago
Author/Presenter: Dr. Muhsinah Morris
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Student Engagement Doesn’t Have to Suck appeared first on Security Boulevard.
Marc Handelman
CVE-2023-33518 | OpenEnergyMonitor EmonCMS 11 Web Request information disclosure (Issue 1856)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in OpenEnergyMonitor EmonCMS 11. This issue affects some unknown processing of the component Web Request Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2023-33518. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-33693 | EasyPlayerPro-Win up to 3.6.19.0823 XML denial of service
1 year 3 months ago
A vulnerability was found in EasyPlayerPro-Win up to 3.6.19.0823. It has been classified as problematic. Affected is an unknown function of the component XML Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-33693. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-33524 | Advent Tamale RMS up to 23.0 Configuration Backup File path traversal
1 year 3 months ago
A vulnerability classified as critical was found in Advent Tamale RMS up to 23.0. This vulnerability affects unknown code of the component Configuration Backup File Handler. The manipulation leads to path traversal.
This vulnerability was named CVE-2023-33524. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33659 | emqx NanoMQ 0.17.2 mqtt_parser.c nmq_subinfo_decode heap-based overflow (Issue 1154)
1 year 3 months ago
A vulnerability was found in emqx NanoMQ 0.17.2. It has been rated as problematic. Affected by this issue is the function nmq_subinfo_decode of the file mqtt_parser.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2023-33659. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-33530 | Tenda G103 1.0.0.5 Web Management command injection
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Tenda G103 1.0.0.5. This issue affects some unknown processing of the component Web Management. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2023-33530. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-33532 | Netgear R6250 1.0.4.48 Web Management command injection
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Netgear R6250 1.0.4.48. Affected is an unknown function of the component Web Management. The manipulation leads to command injection.
This vulnerability is traded as CVE-2023-33532. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-33533 | Netgear D6220/D8500/R6700/R6900 Web Management command injection
1 year 3 months ago
A vulnerability has been found in Netgear D6220, D8500, R6700 and R6900 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Web Management. The manipulation leads to command injection.
This vulnerability is known as CVE-2023-33533. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com