The Russian RomCom group exploited Firefox and Tor Browser zero-day vulnerabilities in attacks on users in Europe and North America. Russian-based cybercrime group RomCom (aka UAT-5647, Storm-0978, Tropical Scorpius, UAC-0180, UNC2596) exploited two Firefox and Tor Browser zero-day vulnerabilities in recent attacks on users across Europe and North America. The first zero-day exploited by the Russian group, is a use-after-free […]
A vulnerability, which was classified as critical, has been found in Creloaded CRE Loaded 6.2. Affected by this issue is some unknown functionality of the file product_info.php. The manipulation of the argument products_id leads to sql injection.
This vulnerability is handled as CVE-2009-1403. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in Pastel CMS 0.8.0. This affects an unknown part of the file admin.php. The manipulation of the argument (Username) leads to sql injection.
This vulnerability is uniquely identified as CVE-2009-1404. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in e107 CMS up to 0.7.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file usersettings.php. The manipulation of the argument hide leads to sql injection.
This vulnerability is handled as CVE-2009-1409. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in Rens Rikkerink FunGamez and classified as critical. Affected by this vulnerability is an unknown functionality of the component Login. The manipulation of the argument username leads to sql injection.
This vulnerability is known as CVE-2009-1487. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Rens Rikkerink FunGamez and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument module leads to path traversal.
This vulnerability is handled as CVE-2009-1488. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Rens Rikkerink Fungamez. It has been classified as critical. This affects an unknown part. The manipulation of the argument cookie leads to improper authentication.
This vulnerability is uniquely identified as CVE-2009-1489. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in CoolPlayer 2.19.1. It has been classified as very critical. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2009-1437. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Neocrome Seditio 1.0. This vulnerability affects unknown code of the file events/inc/events.inc.php. The manipulation of the argument c leads to sql injection.
This vulnerability was named CVE-2009-1411. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in Studiolounge Address Book 2.5. This affects an unknown part of the file upload-file.php of the component Address Book. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2009-1483. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in e-cart Free Shopping Cart. It has been classified as critical. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2009-1447. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in Microsoft Windows XP. This affects an unknown part. The manipulation leads to improper resource management.
This vulnerability is uniquely identified as CVE-2009-1511. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Anoochit Chalothorn Tiny Blogr 1.0.0. Affected is an unknown function of the file class.eport.php. The manipulation of the argument txtUsername leads to sql injection.
This vulnerability is traded as CVE-2009-1453. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in KDE 1.1/1.1.1/1.2/2.0 Beta. It has been rated as critical. Affected by this issue is some unknown functionality of the file kscd. The manipulation of the argument SHELL as part of Environment Variable leads to improper privilege management.
This vulnerability is handled as CVE-2000-0393. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.