Aggregator
墨菲安全出席蚂蚁举办的切面会客厅,以供应链视角推动企业软件安全架构升级
5 months ago
切面会客厅:平行切面技术实践应用专场
墨菲安全出席蚂蚁举办的切面会客厅,以供应链视角推动企业软件安全架构升级
5 months ago
切面会客厅:平行切面技术实践应用专场
CVE-2009-1814 | Jevontech PHPenpals 1.1 mail.php ID sql injection (EDB-8706 / BID-34996)
5 months ago
A vulnerability was found in Jevontech PHPenpals 1.1. It has been classified as critical. This affects an unknown part of the file mail.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2009-1814. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2006-0074 | Jevontech PHPenpals 1.1 profile.php personalID sql injection (EDB-8706 / Nessus ID 21133)
5 months ago
A vulnerability classified as critical was found in Jevontech PHPenpals 1.1. Affected by this vulnerability is an unknown functionality of the file profile.php. The manipulation of the argument personalID leads to sql injection.
This vulnerability is known as CVE-2006-0074. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2009-1768 | Ramazeiten Ramazaitencms0.9.7.6 up to 0.9.8 download.php file path traversal (EDB-8700 / XFDB-50572)
5 months ago
A vulnerability was found in Ramazeiten Ramazaitencms0.9.7.6 up to 0.9.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the file download.php. The manipulation of the argument file leads to path traversal.
This vulnerability is handled as CVE-2009-1768. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1819 | 2daybiz Custom T-shirt Design Script product.php id sql injection (EDB-8702 / BID-34992)
5 months ago
A vulnerability, which was classified as critical, has been found in 2daybiz Custom T-shirt Design Script. Affected by this issue is some unknown functionality of the file product.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2009-1819. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1820 | 2daybiz Custom T-shirt Design Script product.php id cross site scripting (EDB-8702 / BID-34992)
5 months ago
A vulnerability, which was classified as problematic, was found in 2daybiz Custom T-shirt Design Script. This affects an unknown part of the file product.php. The manipulation of the argument id leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2009-1820. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1821 | DMXReady Registration Manager 1.1 access control (EDB-8705 / XFDB-50915)
5 months ago
A vulnerability has been found in DMXReady Registration Manager 1.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2009-1821. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2009-1815 | Sonicspot Audioactive Player 1.93b memory corruption (EDB-8698 / BID-34987)
5 months ago
A vulnerability was found in Sonicspot Audioactive Player 1.93b. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2009-1815. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Защита локальных администраторов в Windows 11: полное руководство по настройке и работе
5 months ago
Обзор новой функции Administrator Protection в Windows 11, особенностей работы «теневых аккаунтов» и защиты прав локального администратора.
zsh 安装与配置,使用 oh-my-zsh 美化SSH终端
5 months ago
传统的 bash 功能比较简陋,且不美观。本文基于 Ubuntu22.04 LTS 系统,安装 zsh,并使用 oh-my-zsh 对终端进行美化。Oh My Zsh 是基于 zsh 命令行的一...
黑海洋
发布 PoC:Windows 驱动程序中的整数溢出漏洞可导致权限升级
5 months ago
安全客
Cyber-Attacks Could Impact Romanian Presidential Race, Officials Claim
5 months ago
Romania’s national security council suggested that Russia is behind these attacks, amid a court order for a recount of votes in the first round of the country’s presidential election
CVE-2017-3528 | Oracle E-Business Suite 12.1.3/12.2.3/12.2.4/12.2.5/12.2.6 Applications Framework /OA_HTML/cabo/jsps/a.jsp redirect access control (EDB-43592 / Nessus ID 99479)
5 months ago
A vulnerability was found in Oracle E-Business Suite 12.1.3/12.2.3/12.2.4/12.2.5/12.2.6. It has been declared as critical. This vulnerability affects unknown code of the file /OA_HTML/cabo/jsps/a.jsp of the component Applications Framework. The manipulation of the argument redirect with the input /\example.com leads to improper access controls.
This vulnerability was named CVE-2017-3528. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Fog
5 months ago
cohenido
Кризис контента: ИИ стал лидером мнений на LinkedIn
5 months ago
С момента появления генеративного ИИ публикации в интернете навсегда поменяли свой облик.
NHS 重大“网络事件”迫使医院使用笔和纸
5 months ago
安全客
90 миллионов за 365 дней: как лжезащитники превратили жизнь пожилой москвички в кошмар
5 months ago
Женщина продавала всё, чтобы «защитить» свои деньги.
评论 | 治理涉企谣言,落实数字平台“看门人”职责
5 months ago
近年来,网络空间的造谣现象持续存在,尤其通过对企业和企业家的造谣获取流量,成为一种非法获利方式。治理谣言是一项综合工程,首当其冲的是,数字平台应当履行好“看门人”职责。谣言产生于平台,事前防谣的第一责任人是数字平台。