Aggregator
CVE-2007-1790 | Kaqoo Auction Software user_info.inc.php install_root privileges management (EDB-3607 / XFDB-33335)
10 months 1 week ago
A vulnerability was found in Kaqoo Auction Software and classified as critical. Affected by this issue is some unknown functionality of the file include/display/user_info.inc.php. The manipulation of the argument install_root leads to improper privilege management.
This vulnerability is handled as CVE-2007-1790. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-1790 | Kaqoo Auction Software activate.inc.php install_root code injection (EDB-3607 / XFDB-33335)
10 months 1 week ago
A vulnerability has been found in Kaqoo Auction Software and classified as critical. Affected by this vulnerability is an unknown functionality of the file include/display/activate.inc.php. The manipulation of the argument install_root leads to code injection.
This vulnerability is known as CVE-2007-1790. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-1790 | Kaqoo Auction Software admin_balance.inc.php install_root code injection (EDB-3607 / XFDB-33335)
10 months 1 week ago
A vulnerability, which was classified as critical, was found in Kaqoo Auction Software. Affected is an unknown function of the file include/display/admin_balance.inc.php. The manipulation of the argument install_root leads to code injection.
This vulnerability is traded as CVE-2007-1790. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-2540 | Apple macOS up to 10.12.4 WindowServer Memory access control (HT207797 / Nessus ID 100270)
10 months 1 week ago
A vulnerability classified as problematic has been found in Apple macOS up to 10.12.4. Affected is an unknown function of the component WindowServer. The manipulation leads to improper access controls (Memory).
This vulnerability is traded as CVE-2017-2540. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2537 | Apple macOS up to 10.12.4 WindowServer memory corruption (HT207797 / Nessus ID 100270)
10 months 1 week ago
A vulnerability was found in Apple macOS up to 10.12.4. It has been classified as critical. This affects an unknown part of the component WindowServer. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2017-2537. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-1790 | Kaqoo Auction Software user_feedback.inc.php install_root code injection (EDB-3607 / XFDB-33335)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Kaqoo Auction Software. This issue affects some unknown processing of the file include/display/user_feedback.inc.php. The manipulation of the argument install_root leads to code injection.
The identification of this vulnerability is CVE-2007-1790. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
刑诉法修改前瞻|叶青:修法应建立电子数据证据审查认定规则
10 months 1 week ago
作者简介:叶青,华东政法大学校长、刑事法学院教授、博导,中国刑事诉讼法学研究会副会长。
【邮件取证方法介绍】
10 months 1 week ago
CVE-2014-5806 | Wargaming World of Tanks Assistant 1.7.5 X.509 Certificate cryptographic issues (VU#582497)
10 months 1 week ago
A vulnerability was found in Wargaming World of Tanks Assistant 1.7.5. It has been classified as critical. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-5806. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
面对智能设备安全隐患,5个有效的解决策略
10 months 1 week ago
物联网安全指南,全面分析物联网安全背后五大安全策略。
CVE-2013-5945 | D-Link DIR Router 150/250/500/1000 scgi-bin/platform.cgi Password sql injection (EDB-30062 / OSVDB-100841)
10 months 1 week ago
A vulnerability classified as critical was found in D-Link DIR Router 150/250/500/1000. This vulnerability affects unknown code of the file scgi-bin/platform.cgi. The manipulation of the argument Password leads to sql injection.
This vulnerability was named CVE-2013-5945. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2623 | rpm-ostree/rpm-ostree-client prior 2017.3 GPG Signature certificate validation (FEDORA-2017-788129b61c / Nessus ID 97867)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in rpm-ostree and rpm-ostree-client. Affected by this issue is some unknown functionality of the component GPG Signature Handler. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2017-2623. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2661 | Clusterlabs PCS up to 0.9.156 Node Name cross site scripting (Bug 1428948 / Nessus ID 99176)
10 months 1 week ago
A vulnerability classified as problematic was found in Clusterlabs PCS up to 0.9.156. Affected by this vulnerability is an unknown functionality of the component Node Name Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2017-2661. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-6896 | DIGISOL DG-HR1400 1.00.02 Session Cookie access control (EDB-41633)
10 months 1 week ago
A vulnerability was found in DIGISOL DG-HR1400 1.00.02. It has been declared as critical. This vulnerability affects unknown code of the component Session Cookie Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2017-6896. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-7786 | Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 Access Restriction Licenseinformation.jsp access control (EDB-44469)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5. This issue affects some unknown processing of the file Licenseinformation.jsp of the component Access Restriction. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2016-7786. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2784 | ARM mbed TLS up to 1.3.18/2.1.6/2.4.1 X.509 Certificate certificate validation (FEDORA-2017-922652dd9c / Nessus ID 97969)
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in ARM mbed TLS up to 1.3.18/2.1.6/2.4.1. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to improper certificate validation.
The identification of this vulnerability is CVE-2017-2784. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2008-6202 | Jakob-persson CoBaLT 1.0 urun.asp id sql injection (EDB-5373 / XFDB-48835)
10 months 1 week ago
A vulnerability was found in Jakob-persson CoBaLT 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file urun.asp. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2008-6202. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2014-5805 | Wamba Dating for everyone - Mamba! 3.5 X.509 Certificate cryptographic issues (VU#582497)
10 months 1 week ago
A vulnerability was found in Wamba Dating for everyone - Mamba! 3.5 and classified as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-5805. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2014-5804 | Mail.Ru Mail.Ru Dating 3.0 X.509 Certificate cryptographic issues (VU#582497)
10 months 1 week ago
A vulnerability has been found in Mail.Ru Mail.Ru Dating 3.0 and classified as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-5804. Access to the local network is required for this attack. There is no exploit available.
vuldb.com