Aggregator
CVE-2006-6029 | Property Pro 1.0 Login vir_login.asp sql injection (EDB-2774 / BID-24992)
7 months ago
A vulnerability has been found in Property Pro 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file vir_login.asp of the component Login. The manipulation leads to sql injection.
This vulnerability is known as CVE-2006-6029. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Microsoft testing Windows 11 support for third-party passkeys
7 months ago
Microsoft is now testing WebAuthn API updates that add support for support for using third-party passkey providers for Windows 11 passwordless authentication. [...]
Sergiu Gatlan
CVE-2024-11231 | codemstory 우커머스 네이버페이 Plugin up to 3.3.7 on WordPress Shortcode mnp_purchase cross site scripting
7 months ago
A vulnerability was found in codemstory 우커머스 네이버페이 Plugin up to 3.3.7 on WordPress. It has been classified as problematic. This affects the function mnp_purchase of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11231. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11229 | codemstory 코드엠샵 소셜톡 Plugin up to 1.1.18 on WordPress Shortcode add_plus_friends/add_plus_talk cross site scripting
7 months ago
A vulnerability was found in codemstory 코드엠샵 소셜톡 Plugin up to 1.1.18 on WordPress and classified as problematic. Affected by this issue is the function add_plus_friends/add_plus_talk of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11229. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11228 | codemstory 우커머스 결제 플러그인 Plugin up to 5.1.4 on WordPress Shortcode pafw_instant_payment cross site scripting
7 months ago
A vulnerability has been found in codemstory 우커머스 결제 플러그인 Plugin up to 5.1.4 on WordPress and classified as problematic. Affected by this vulnerability is the function pafw_instant_payment of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11228. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11034 | wpbean Request a Quote for WooCommerce and Elementor Plugin Shortcode fire_contact_form code injection
7 months ago
A vulnerability, which was classified as critical, was found in wpbean Request a Quote for WooCommerce and Elementor Plugin up to 1.4 on WordPress. Affected is the function fire_contact_form of the component Shortcode Handler. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-11034. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
МКС и медицина будущего: как микрогравитация усиливает регенеративные свойства стволовых клеток
7 months ago
Стволовые клетки показали невероятные результаты в невесомости.
Hunters
7 months ago
cohenido
CVE-2024-35160 | IBM Watson Query for Cloud Pak for Data session expiration
7 months ago
A vulnerability, which was classified as problematic, has been found in IBM Watson Query for Cloud Pak for Data and Db2 Big SQL on Cloud Pak for Data. This issue affects some unknown processing. The manipulation leads to session expiration.
The identification of this vulnerability is CVE-2024-35160. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Ranch Has Leaked the Data of Andrew Tate's The Real World
7 months ago
Ranch Has Leaked the Data of Andrew Tate's The Real World
Dark Web Informer - Cyber Threat Intelligence
CVE-2006-0277 | Oracle E-Business Suite 11.5.10 Applications Technology Stack Remote Code Execution (VU#545804 / XFDB-24321)
7 months ago
A vulnerability, which was classified as very critical, was found in Oracle E-Business Suite 11.5.10. This affects an unknown part of the component Applications Technology Stack. The manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2006-0277. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-0273 | Oracle Application Server 9.0.4.2 cross site scripting (VU#545804 / Nessus ID 57619)
7 months ago
A vulnerability was found in Oracle Application Server 9.0.4.2. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2006-0273. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-0274 | Oracle Application Server 9.0.4.2 cross site scripting (VU#545804 / Nessus ID 57619)
7 months ago
A vulnerability classified as critical has been found in Oracle Application Server 9.0.4.2. Affected is an unknown function. The manipulation leads to basic cross site scripting.
This vulnerability is traded as CVE-2006-0274. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-0276 | Oracle Collaboration Suite 9.0.4.2 Remote Code Execution (VU#545804 / XFDB-24321)
7 months ago
A vulnerability, which was classified as very critical, has been found in Oracle Collaboration Suite 9.0.4.2. Affected by this issue is some unknown functionality. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2006-0276. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2006-0272 | Oracle Oracle9i Standard 9.2.0.7 memory corruption (VU#545804 / Nessus ID 56051)
7 months ago
A vulnerability was found in Oracle Oracle9i Standard 9.2.0.7. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2006-0272. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
微软开放预览其受争议的 Windows Recall
7 months ago
微软向部分使用 Copilot+ PC 的用户开放预览其受争议的 Windows Recall 功能。Recall 通过每隔数秒进行一次屏幕截图,在本地创造可搜索数字记忆。该功能引发了隐私和安全方面的争议,Recall 显然会将用户的私密信息都截图保存下来,微软因为争议而推迟了 Recall 的发布。最新的开放预览仅提供给高通 Snapdragon X Elite 和 Plus Copilot+ PC 的用户,运行版本为 Windows Insider build 26120.2415。为减少隐私争议,Recall 将强制使用加密,可选择激活,需要 Windows Hello 身份验证。该功能还需要 Secure Boot、BitLocker 加密,会尝试自动模糊密码和信用卡号等敏感数据。
UNDERGROUND-NET Defaced the Website of Trushi Consultancy
7 months ago
UNDERGROUND-NET Defaced the Website of Trushi Consultancy
Dark Web Informer - Cyber Threat Intelligence
DEF CON 32 – Troll Trapping Through TAS Tools Exposing Speedrunning Cheaters
7 months ago
Authors/Presenters: Allan Cecil
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Troll Trapping Through TAS Tools Exposing Speedrunning Cheaters appeared first on Security Boulevard.
Marc Handelman
SecWiki News 2024-11-23 Review
7 months ago