Aggregator
CVE-2008-4341 | MyBlog 0.9.8 add.php admin=yes access control (EDB-6531 / XFDB-45576)
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in MyBlog 0.9.8. Affected by this issue is some unknown functionality of the file add.php. The manipulation of the argument admin=yes leads to improper access controls.
This vulnerability is handled as CVE-2008-4341. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6025 | openElec 2.02/3.00/3.01 obj path traversal (EDB-6530 / XFDB-45299)
1 year 4 months ago
A vulnerability classified as critical was found in openElec 2.02/3.00/3.01. This vulnerability affects unknown code. The manipulation of the argument obj leads to path traversal.
This vulnerability was named CVE-2008-6025. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6028 | University of Queensland Fez 1.3/2.0 list.php parent_id sql injection (EDB-6535 / XFDB-45332)
1 year 4 months ago
A vulnerability has been found in University of Queensland Fez 1.3/2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file list.php. The manipulation of the argument parent_id leads to sql injection.
This vulnerability is known as CVE-2008-6028. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6036 | BaseBuilder 1.0/1.0.3/2.0/2.0.1 main.inc.php mj_config[src_path] code injection (EDB-6533 / XFDB-45337)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in BaseBuilder 1.0/1.0.3/2.0/2.0.1. This affects an unknown part of the file main.inc.php. The manipulation of the argument mj_config[src_path] leads to code injection.
This vulnerability is uniquely identified as CVE-2008-6036. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-5840 | phpicalendar Alpha Test up to 2.24 access control (EDB-6526 / XFDB-45338)
1 year 4 months ago
A vulnerability classified as critical was found in phpicalendar Alpha Test up to 2.24. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2008-5840. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6029 | BuzzyWall 1/1.3/1.3.1 search.php search sql injection (EDB-6527 / BID-31308)
1 year 4 months ago
A vulnerability was found in BuzzyWall 1/1.3/1.3.1 and classified as critical. Affected by this issue is some unknown functionality of the file search.php. The manipulation of the argument search leads to sql injection.
This vulnerability is handled as CVE-2008-6029. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6032 | WSN Links 4.0.34p comments.php id sql injection (EDB-6529 / XFDB-48534)
1 year 4 months ago
A vulnerability was found in WSN Links 4.0.34p. It has been rated as critical. This issue affects some unknown processing of the file comments.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2008-6032. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6033 | WSN Links 2.20 comments.php id sql injection (EDB-6525 / BID-31302)
1 year 4 months ago
A vulnerability classified as critical has been found in WSN Links 2.20. Affected is an unknown function of the file comments.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2008-6033. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-6031 | WSN Links 2.22 vote.php id sql injection (EDB-6524 / BID-31305)
1 year 4 months ago
A vulnerability was found in WSN Links 2.22. It has been declared as critical. This vulnerability affects unknown code of the file vote.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2008-6031. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning
1 year 4 months ago
Cybersecurity researchers have disclosed six security flaws in the Ollama artificial intelligence (AI) framework that could be exploited by a malicious actor to perform various actions, including denial-of-service, model poisoning, and model theft.
"Collectively, the vulnerabilities could allow an attacker to carry out a wide-range of malicious actions with a single HTTP request, including
The Hacker News
From Garbage to Great: The Data-First Path to AIOps
1 year 4 months ago
We’re past the days of "garbage in, garbage out." Today, just one bad dataset fed into artificial intelligence (AI) technology and—voilà: “garbage AI.” So, if AI-driven initiatives such as artificial intelligence for IT operations (AIOps) are to succeed, they need consistent AI-ready data of the highest quality...
Anthony Cote
微软因隐私问题推迟Windows Copilot+ Recall发布
1 year 4 months ago
安全客
Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)
1 year 4 months ago
Synology has released fixes for an unauthenticated “zero-click” remote code execution flaw (CVE-2024-10443, aka RISK:STATION) affecting its popular DiskStation and BeeStation network attached storage (NAS) devices. About CVE-2024-10443 CVE-2024-10443 was discovered by Rick de Jager, a security researcher at Midnight Blue, and has been exploited at the Pwn2Own Ireland 2024 hacking competition ten days ago. The specifics of CVE-2024-10443 are under wraps for the moment, but we know that it may allow unauthenticated attackers to … More →
The post Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443) appeared first on Help Net Security.
Zeljka Zorz
Minol策略分配
1 year 4 months ago
给pic分配权限,基于S3的都能用。
{
"Version": "2012-10-17",
"Statement": [
{
"Effec...
黑海洋
粉丝制作《半条命2:第三章》
1 year 4 months ago
在《半条命2》发行二十周年之际,一群粉丝正在使用 UE5(虚幻引擎5)引擎制作 Valve 取消的《半条命2:第三章》,以为这款著名游戏划上句号。该项目被称为 Project Borealis,其序章《Project Borealis: Prologue》已经在 Steam 平台上线,发行日期尚未宣布。序章讲述了发生在 Project Borealis 前的故事,玩家将扮演弗里德曼博士(Gordon Freeman)进入埋在一层雪下的 Ravenholm 镇。
RansomHub
1 year 4 months ago
cohenido
Загадочный трафик и ложные блокировки: зачем хакеры атакуют узлы Tor?
1 year 4 months ago
Угроза безопасности нарастает, и её масштаб уже не скрыть.
CVE-2015-8936 | squidGuard up to 1.4 Blocked Site Link squidGuard.cgi cross site scripting (Nessus ID 92266 / ID 170008)
1 year 4 months ago
A vulnerability was found in squidGuard up to 1.4. It has been rated as problematic. This issue affects some unknown processing of the file squidGuard.cgi of the component Blocked Site Link Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2015-8936. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Live Webinar | Reimagine Your Cloud Transformation Journey
1 year 4 months ago