Aggregator
DEF CON 32 – Cultivating M4D SK1LLZ In the DEF CON Community
4 months ago
Authors/Presenters: Yan Shoshitaishvili, Perri Adams
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Cultivating M4D SK1LLZ In the DEF CON Community appeared first on Security Boulevard.
Marc Handelman
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits
4 months ago
A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000 credentials.
The malicious activity is part of a broader attack campaign undertaken by a threat actor, dubbed MUT-1244 (where MUT refers to "mysterious unattributed threat") by Datadog Security Labs, that
The Hacker News
CVE-2024-52836 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.21. This affects an unknown part of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-52836. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52842 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.21. This vulnerability affects unknown code of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-52842. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52841 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability, which was classified as problematic, has been found in Adobe Experience Manager up to 6.5.21. This issue affects some unknown processing of the component Form Field Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-52841. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52843 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability, which was classified as problematic, was found in Adobe Experience Manager up to 6.5.21. Affected is an unknown function of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-52843. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52845 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability has been found in Adobe Experience Manager up to 6.5.21 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-52845. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52834 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability was found in Adobe Experience Manager up to 6.5.21 and classified as problematic. Affected by this issue is some unknown functionality of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-52834. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52835 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability was found in Adobe Experience Manager up to 6.5.21. It has been classified as problematic. This affects an unknown part of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-52835. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52846 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability was found in Adobe Experience Manager up to 6.5.21. It has been declared as problematic. This vulnerability affects unknown code of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-52846. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52847 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability was found in Adobe Experience Manager up to 6.5.21. It has been rated as problematic. This issue affects some unknown processing of the component Form Field Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-52847. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52848 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.21. Affected is an unknown function of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-52848. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52849 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.21. Affected by this vulnerability is an unknown functionality of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-52849. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52850 | Adobe Experience Manager up to 6.5.21 Form Field cross site scripting (apsb24-69 / Nessus ID 212264)
4 months ago
A vulnerability, which was classified as problematic, has been found in Adobe Experience Manager up to 6.5.21. Affected by this issue is some unknown functionality of the component Form Field Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-52850. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
FTC warns of online task job scams hooking victims like gambling
4 months ago
The Federal Trade Commission (FTC) warns about a significant rise in gambling-like online job scams, known as "task scams," that draw people into earning cash through repetitive tasks, with the promises of earning more if they deposit their own money. [...]
Bill Toulas
CVE-2024-45103 | Lenovo XClarity Administrator up to 4.0 Web Interface improper ownership management
4 months ago
A vulnerability was found in Lenovo XClarity Administrator up to 4.0. It has been classified as problematic. Affected is an unknown function of the component Web Interface. The manipulation leads to improper ownership management.
This vulnerability is traded as CVE-2024-45103. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45104 | Lenovo XClarity Administrator up to 4.0 Web API Call improper ownership management
4 months ago
A vulnerability was found in Lenovo XClarity Administrator up to 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Web API Call. The manipulation leads to improper ownership management.
This vulnerability is known as CVE-2024-45104. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29404 | Razer Synapse 3.9.131.20813 Profiles export command injection
4 months ago
A vulnerability classified as problematic has been found in Razer Synapse 3.9.131.20813. Affected is an unknown function of the component Profiles. The manipulation of the argument export leads to command injection.
This vulnerability is traded as CVE-2024-29404. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2024-8259 | Eryaz Information Technologies NatraCar B2B Dealer Management Program up to 09.12.2024 sql injection
4 months ago
A vulnerability, which was classified as critical, has been found in Eryaz Information Technologies NatraCar B2B Dealer Management Program up to 09.12.2024. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-8259. The attack may be launched remotely. There is no exploit available.
vuldb.com