Continuing from the previous blog article, this entry introduces the presentations on the 2nd day of JSAC2025. Observation of phishing criminal groups related to illegal money transfers and Mizuho Bank’s countermeasures -Fighting against phishing site malware ‘KeepSpy’- Speaker: Tsukasa Takeuchi,...
A vulnerability, which was classified as critical, was found in SourceCodester PHP Task Management System 1.0. This affects an unknown part of the file admin-manage-user.php. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-28556. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in Squirrly SEO Plugin up to 12.3.19 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-43286. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in Cisco Identity Services Engine Software. This affects an unknown part of the component REST API. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-20417. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Cisco Identity Services Engine Software. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-20486. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in DedeCMS 5.7.115. This vulnerability affects unknown code of the file file_manage_view.php?fmdo=newfile&activepath. The manipulation leads to command injection.
This vulnerability was named CVE-2024-42636. Access to the local network is required for this attack. There is no exploit available.
A vulnerability was found in Lester Chan WP-PostRatings Plugin up to 1.91.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-39659. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in Popup Maker Plugin up to 1.19.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-7054. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Cisco Identity Services Engine Software. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to incorrect privilege assignment.
This vulnerability is handled as CVE-2024-20466. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in DedeCMS 5.7.115. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-46373. The attack can be initiated remotely. There is no exploit available.