Aggregator
.NET 内网攻防实战电子报刊
1 year 4 months ago
.NET 红队武器库和资源集合 (第43期)
1 year 4 months ago
The Club Penguin Experience - 6,342 breached accounts
1 year 4 months ago
Here's an overview of the various breaches that have been consolidated into this Have I Been
CVE-2012-3001 | Mutiny Standard 4.4-1.12/4.5-1.03/4.5-1.05/4.5-1.07/4.5-1.10 os command injection (VU#841851 / EDB-24888)
1 year 4 months ago
A vulnerability classified as critical was found in Mutiny Standard 4.4-1.12/4.5-1.03/4.5-1.05/4.5-1.07/4.5-1.10. This vulnerability affects unknown code. The manipulation leads to os command injection.
This vulnerability was named CVE-2012-3001. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2005-4299 | Atlantpro.com Atlant Pro up to 4.02 atl.cgi cross site scripting (EDB-26845 / BID-15886)
1 year 4 months ago
A vulnerability was found in Atlantpro.com Atlant Pro up to 4.02. It has been rated as problematic. Affected by this issue is some unknown functionality of the file atl.cgi. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2005-4299. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-2955 | KAPhotoservice 7.5 edtalbum.asp albumid cross site scripting (EDB-28002 / XFDB-27073)
1 year 4 months ago
A vulnerability classified as problematic has been found in KAPhotoservice 7.5. Affected is an unknown function of the file edtalbum.asp. The manipulation of the argument albumid leads to basic cross site scripting.
This vulnerability is traded as CVE-2006-2955. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
New Windows Driver Signature bypass allows kernel rootkit installs
1 year 4 months ago
Attackers can downgrade Windows kernel components to bypass security features such as Driver Signature Enforcement and deploy rootkits on fully patched systems. [...]
Bill Toulas
CVE-2002-1069 | D-Link DI-804 4.68 privileges management (XFDB-9967 / BID-5553)
1 year 4 months ago
A vulnerability classified as critical was found in D-Link DI-804 4.68. This vulnerability affects unknown code. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2002-1069. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CERT-UA Identifies Malicious RDP Files in Latest Attack on Ukrainian Entities
1 year 4 months ago
Cyber Attack / Threat IntelligenceThe Computer Emergency Response Team of Ukraine (CERT-UA) has de
An Update on Windows Downdate
1 year 4 months ago
A SafeBreach researcher took over the Windows Update process to make the term “fully patched” meaningless on any Windows machine in the world.
The post An Update on Windows Downdate appeared first on SafeBreach.
The post An Update on Windows Downdate appeared first on Security Boulevard.
Alon Leviev
CVE-2000-0245 | SGI IRIX up to 6.2 Objectserver Daemon User privileges management (EDB-19822 / Nessus ID 10384)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in SGI IRIX up to 6.2. This affects an unknown part of the component Objectserver Daemon. The manipulation leads to improper privilege management (User).
This vulnerability is uniquely identified as CVE-2000-0245. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2002-1068 | D-Link DP-303 Web Server POST Request denial of service (XFDB-9703 / BID-5330)
1 year 4 months ago
A vulnerability classified as problematic has been found in D-Link DP-303. This affects an unknown part of the component Web Server. The manipulation as part of POST Request leads to denial of service.
This vulnerability is uniquely identified as CVE-2002-1068. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2002-1051 | Ehud Gavron TrACESroute 6.0/6.1/6.1.1 -T memory corruption (Nessus ID 15091 / XFDB-9291)
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in Ehud Gavron TrACESroute 6.0/6.1/6.1.1. This issue affects some unknown processing. The manipulation of the argument -T leads to memory corruption.
The identification of this vulnerability is CVE-2002-1051. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
FBI, CISA investigating China-linked telecom hacks following reports of intrusions on Trump, Harris phones
1 year 4 months ago
U.S. agencies are investigating allegations that hackers connected to the government of China breac
CVE-2017-6994 | Apple watchOS up to 3.2.1 AVEVideoEncoder Application memory corruption (EDB-42555 / BID-98571)
1 year 4 months ago
A vulnerability was found in Apple watchOS up to 3.2.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component AVEVideoEncoder. The manipulation as part of Application leads to memory corruption.
This vulnerability is handled as CVE-2017-6994. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
胡闹搬家(Moving Out)在 Epic 游戏商店限免|经典多人游戏,最多4人
1 year 4 months ago
Home业界消息胡闹搬家(Moving Out)在 Epic 游戏商店限免|经典多人游戏,最多4人
CVE-2002-1037 | Michael Dean Double Choco Latte up to 20020706 cross site scripting (XFDB-9532 / BID-5182)
1 year 4 months ago
A vulnerability was found in Michael Dean Double Choco Latte up to 20020706. It has been classified as problematic. This affects an unknown part. The manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2002-1037. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-0983 | Adobe Flash Player use after free (RHSA-2016:0166 / Nessus ID 88638)
1 year 4 months ago
A vulnerability was found in Adobe Flash Player. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to use after free.
This vulnerability is handled as CVE-2016-0983. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9772 | Uix Shortcodes Plugin up to 1.9.9 on WordPress code injection
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Uix Shortcodes Plugin up to 1.9.9 on WordPress. This issue affects some unknown processing. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-9772. The attack may be initiated remotely. There is no exploit available.
vuldb.com