Aggregator
情报之战:以色列数十年情报布局如何瓦解真主党
8 months 2 weeks ago
Cybercriminals tighten their grip on organizations
8 months 2 weeks ago
Cybercriminals are using a variety of new methods to target organizations across industries. In this article, we examine the most pressing trends and findings from the 2024 surveys on the growing threat of cybercrime. Social engineering scams sweep through financial institutions North American financial institutions fielded 10 times more reports of social engineering scams in 2024 than they did a year ago. Account-opening fraud declined by nearly 60% in the last year, as banks implemented additional controls, … More →
The post Cybercriminals tighten their grip on organizations appeared first on Help Net Security.
Help Net Security
CVE-2001-1524 | Francisco Burzi PHP-Nuke up to 5.3.1 user.php uname/title/letter/file/upload/fname cross site scripting (EDB-21166 / XFDB-7654)
8 months 2 weeks ago
A vulnerability was found in Francisco Burzi PHP-Nuke up to 5.3.1 and classified as problematic. This issue affects some unknown processing of the file user.php. The manipulation of the argument uname/title/letter/file/upload/fname leads to basic cross site scripting.
The identification of this vulnerability is CVE-2001-1524. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Simple Prompts to get the System Prompts
8 months 2 weeks ago
CVE-2012-3814 | Pippin Williamson Font Uploader 1.2.4 File Upload font-upload.php access control (EDB-18994 / ID 13017)
8 months 2 weeks ago
A vulnerability was found in Pippin Williamson Font Uploader 1.2.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file font-upload.php of the component File Upload. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2012-3814. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2012-3811 | Avaya IP Office Customer Call Reporter 7.x/8.x ImageUpload.ashx PHP File unrestricted upload (ZDI-12-106 / EDB-21847)
8 months 2 weeks ago
A vulnerability was found in Avaya IP Office Customer Call Reporter 7.x/8.x. It has been declared as critical. This vulnerability affects unknown code of the file ImageUpload.ashx. The manipulation as part of PHP File leads to unrestricted upload.
This vulnerability was named CVE-2012-3811. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-3828 | Joomla CMS 2.5.3 cross site scripting (ID 12597 / XFDB-75223)
8 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Joomla CMS 2.5.3. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2012-3828. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2012-3949 | Cisco Unified Communications Manager up to 8.5(1)su3 SIP Network Packet input validation (cisco-sa-20120926-cucm / Nessus ID 67203)
8 months 2 weeks ago
A vulnerability classified as critical was found in Cisco Unified Communications Manager up to 8.5(1)su3. Affected by this vulnerability is an unknown functionality of the component SIP. The manipulation as part of Network Packet leads to improper input validation.
This vulnerability is known as CVE-2012-3949. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4930 | Google Chrome Encryption cryptographic issues (Nessus ID 63402 / ID 165422)
8 months 2 weeks ago
A vulnerability was found in Google Chrome. It has been classified as problematic. This affects an unknown part of the component Encryption. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2012-4930. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13035 | code-projects Chat System 1.0 /admin/update_user.php id sql injection
8 months 2 weeks ago
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/update_user.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-13035. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-13036 | code-projects Chat System 1.0 /admin/update_room.php id/name/password sql injection
8 months 2 weeks ago
A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/update_room.php. The manipulation of the argument id/name/password leads to sql injection.
The identification of this vulnerability is CVE-2024-13036. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
现场监看,即时修图:iPad + 像素蛋糕 App 拍摄工作流
8 months 2 weeks ago
在笔者写过的文章下面,总有人刷「道理我都懂,模特上哪找?」这样的评论。想来对于人像摄影的新手来说,找不到模特拍是阻碍他们进步的最大障碍。对此,笔者的建议就是:去漫展拍。在十多年前,这个赛道还是很轻
CVE-2012-4188 | Mozilla Firefox/Thunderbird 15 Convolve3x3 memory corruption (MFSA 2012-86 / Nessus ID 802995)
8 months 2 weeks ago
A vulnerability was found in Mozilla Firefox and Thunderbird 15 and classified as very critical. Affected by this issue is the function Convolve3x3. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2012-4188. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4187 | Mozilla Firefox/Thunderbird 15 insPos memory corruption (MFSA 2012-86 / Nessus ID 62484)
8 months 2 weeks ago
A vulnerability classified as critical was found in Mozilla Firefox and Thunderbird 15. Affected by this vulnerability is an unknown functionality. The manipulation of the argument insPos leads to memory corruption.
This vulnerability is known as CVE-2012-4187. The attack can be launched remotely. There is no exploit available.
It is recommended to apply the suggested workaround.
vuldb.com
CVE-2012-4166 | Adobe Flash Player 11.1.111.0/11.1.115.11/11.3.300.271 memory corruption (APSB12-19 / ID 120433)
8 months 2 weeks ago
A vulnerability classified as very critical was found in Adobe Flash Player 11.1.111.0/11.1.115.11/11.3.300.271. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2012-4166. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4177 | Ubisoft Uplay Plugin prior 2.0.4 os command injection (EDB-20321 / ID 121038)
8 months 2 weeks ago
A vulnerability has been found in Ubisoft Uplay Plugin and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to os command injection.
This vulnerability is known as CVE-2012-4177. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2012-4219 | phpMyAdmin 3.5.0.0/3.5.1.0/3.5.2.0 Error Message show_config_errors.php information disclosure (Nessus ID 74726 / ID 12593)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in phpMyAdmin 3.5.0.0/3.5.1.0/3.5.2.0. This affects an unknown part of the file show_config_errors.php of the component Error Message Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2012-4219. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
隐私号码成黑产作恶重要资源,威胁猎人“隐私小号”标签助企业精准风控
8 months 2 weeks ago
威胁猎人发现,一些黑产通过伪装注册公司的方式,骗取云服务厂商提供的 “隐私保护号码” 服务,进而批量 “开卡”作恶……
隐私号码成黑产作恶重要资源,威胁猎人“隐私小号”标签助企业精准风控
8 months 2 weeks ago
威胁猎人发现,一些黑产通过伪装注册公司的方式,骗取云服务厂商提供的 “隐私保护号码” 服务,进而批量 “开卡”作恶……