Aggregator
【安全圈】安全公司曝光黑客山寨 AI 网站传播木马,涉及 ChatGPT 等平台
1 month 4 weeks ago
CVE-2009-2440 | Jnmsolutions Guestbook 3.0 index.php page cross site scripting (EDB-34806 / SA35760)
1 month 4 weeks ago
A vulnerability was found in Jnmsolutions Guestbook 3.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2009-2440. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-1608 | zlib 4.4.2 file.c copy cross site scripting (EDB-27596 / Nessus ID 21281)
1 month 4 weeks ago
A vulnerability has been found in zlib 4.4.2 and classified as problematic. Affected by this vulnerability is the function copy of the file file.c. The manipulation leads to basic cross site scripting.
This vulnerability is known as CVE-2006-1608. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-3881 | Microsoft Windows 7/Server 2008 R2 NULL Page win32k.sys resource management (MS13-081 / EDB-31576)
1 month 4 weeks ago
A vulnerability was found in Microsoft Windows 7/Server 2008 R2. It has been declared as problematic. This vulnerability affects unknown code of the file win32k.sys of the component NULL Page Handler. The manipulation leads to improper resource management.
This vulnerability was named CVE-2013-3881. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-4812 | PHP up to 5.1.6 _ecalloc code injection (EDB-28760 / Nessus ID 22929)
1 month 4 weeks ago
A vulnerability was found in PHP and classified as critical. Affected by this issue is the function _ecalloc. The manipulation leads to code injection.
This vulnerability is handled as CVE-2006-4812. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-4111 | HP Insight Diagnostics up to 8.1.0.2717 cross site scripting (EDB-35116 / XFDB-64126)
1 month 4 weeks ago
A vulnerability was found in HP Insight Diagnostics up to 8.1.0.2717. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2010-4111. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
越南废除二孩政策
1 month 4 weeks ago
为应对生育率下降,越南政府废除了自 1988 年起实施的二孩政策——也就是禁止每对夫妇生育两个以上的孩子。现在每对夫妇想生多少就生多少,但越南人表示养育成本太高了,生不起。越南卫生部表示,2024 年越南总生育率降至每名妇女生育 1.91 个孩子,低于 2.1 的更替水平。生育率过去四年连续下降:从 2021 年的每名妇女生育 2.11 个孩子降至 2022 年的 2.01 个孩子和 2023 年的 1.96 个孩子。22 岁的办公室职员 Tran Minh Huong 表示没有生育孩子的计划,“虽然我是亚洲人,社会传统认为女性需要结婚生子,但养育孩子的成本太高了。”
Даркнет, как Tinder, только страшнее: глобальная зачистка началась
1 month 4 weeks ago
Спецслужбы мира устроили зачистку от педофилов на 4 континентах.
CVE-2018-6584 | DT Register Extension 3.2.7 on Joomla Request sql injection (EDB-44108)
1 month 4 weeks ago
A vulnerability was found in DT Register Extension 3.2.7 on Joomla. It has been classified as critical. This affects an unknown part. The manipulation as part of Request leads to sql injection.
This vulnerability is uniquely identified as CVE-2018-6584. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2008-1508 | EfesTech E-Kontör ID sql injection (EDB-31476 / XFDB-41419)
1 month 4 weeks ago
A vulnerability classified as critical was found in EfesTech E-Kontör. This vulnerability affects unknown code. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2008-1508. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
From Quarterbacks to CxOs: Why We All Need a Coach
1 month 4 weeks ago
At one time, having a personal coach was just for top-tier athletes, but no longer. Whether you prefer the term "mentor" or "life coach," there’s growth potential for us all to consider.
The post From Quarterbacks to CxOs: Why We All Need a Coach appeared first on Security Boulevard.
Lohrmann on Cybersecurity
CVE-2025-5859 | PHPGurukul Nipah Virus Testing Management System 1.0 /test-details.php assignto sql injection
1 month 4 weeks ago
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /test-details.php. The manipulation of the argument assignto leads to sql injection.
This vulnerability is known as CVE-2025-5859. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5858 | PHPGurukul Nipah Virus Testing Management System 1.0 /patient-report.php searchdata sql injection
1 month 4 weeks ago
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient-report.php. The manipulation of the argument searchdata leads to sql injection.
This vulnerability is traded as CVE-2025-5858. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5857 | code-projects Patient Record Management System 1.0 /urinalysis_record.php itr_no sql injection
1 month 4 weeks ago
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. The manipulation of the argument itr_no leads to sql injection.
The identification of this vulnerability is CVE-2025-5857. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5856 | PHPGurukul BP Monitoring Management System 1.0 /registration.php emailid sql injection
1 month 4 weeks ago
A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection.
This vulnerability was named CVE-2025-5856. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #591443: PHPGurukul Nipah virus (NiV) – Testing Management System 1.0 SQL Injection [Accepted]
1 month 4 weeks ago
Submit #591443 / VDB-311605
Submit #591440: PHPGurukul Nipah virus (NiV) – Testing Management System 1.0 SQL Injection [Accepted]
1 month 4 weeks ago
Submit #591440 / VDB-311604
CVE-2025-5855 | Tenda AC6 15.03.05.16 /goform/SetRebootTimer formSetRebootTimer rebootTime stack-based overflow
1 month 4 weeks ago
A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-5855. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5854 | Tenda AC6 15.03.05.16 /goform/AdvSetLanip fromadvsetlanip lanMask buffer overflow
1 month 4 weeks ago
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow.
This vulnerability is handled as CVE-2025-5854. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com