Aggregator
第114篇:美国NSA量子DNS注入攻击技术,揭秘网络战的隐蔽手段QUANTUMDNS
10 months 3 weeks ago
第114篇:美国NSA量子DNS注入攻击技术,揭秘网络战的隐蔽手段QUANTUMDNS
10 months 3 weeks ago
第114篇:美国NSA量子DNS注入攻击技术,揭秘网络战的隐蔽手段QUANTUMDNS
10 months 3 weeks ago
Part1 前言 大家好,我是ABC_123。在之前的文章中,ABC_123给大家介绍了很多美国NSA的技战法,很多在今天看来仍然是超过大众认知的,今天给大家继续介绍美国NSA的量子DNS的注入攻击
Daily Blog #727: Experimenting with Deepseek v3
10 months 3 weeks ago
Deepseek v3 is an open source AI model that is challenging OpenAI's dominance. I decided to giv
Microsoft Outlook OLE 双重释放漏洞的零点击远程代码执行概念验证
10 months 3 weeks ago
A new proof-of-concept (PoC) has been released for Microsoft Outlook zero
PoC Exploit Released For Critical Microsoft Outlook (CVE-2025-21298) Zero-Click RCE Vulnerability
10 months 3 weeks ago
A new proof-of-concept (PoC) has been released for Microsoft Outlook zero-click remote code execution (RCE) vulnerability in Windows Object Linking and Embedding (OLE), identified as CVE-2025-21298. The PoC demonstrates memory corruption, shedding light on the flaw’s potential for exploitation stemming from a double-free condition in the ole32.dll component, which can lead to serious security risks […]
The post PoC Exploit Released For Critical Microsoft Outlook (CVE-2025-21298) Zero-Click RCE Vulnerability appeared first on Cyber Security News.
Balaji N
每周高级威胁情报解读(2025.01.17~01.23)
10 months 3 weeks ago
Operation(Giỗ Tổ Hùng Vương)hurricane:浅谈新海莲花组织在内存中的技战术;Lazarus 利用Electron程序瞄准加密货币行业;疑似APT29利用Sliver恶意软件攻击德国实体
每周高级威胁情报解读(2025.01.17~01.23)
10 months 3 weeks ago
2025.01.17~01.23 攻击团伙情报Operation(Giỗ Tổ Hùng Vương)hurricane:浅谈新海莲花组织在内存中的技战术Lazarus 利用Electron程序瞄准加
每周高级威胁情报解读(2025.01.17~01.23)
10 months 3 weeks ago
Operation(Giỗ Tổ Hùng Vương)hurricane:浅谈新海莲花组织在内存中的技战术;Lazarus 利用Electron程序瞄准加密货币行业;疑似APT29利用Sliver恶意软件攻击德国实体
How to Test QR Codes in Your Applications
10 months 3 weeks ago
Building quality software is only possible with quality tests. Whether you write test scripts for QA
CVE-2013-7376 | OpenX 2.8.10 plugin-preferences.php group cross-site request forgery (EDB-26624 / OSVDB-94778)
10 months 3 weeks ago
A vulnerability was found in OpenX 2.8.10. It has been classified as problematic. This affects an unknown part of the file plugin-preferences.php. The manipulation of the argument group leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2013-7376. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-4118 | ISPConfig up to 3.0.5.4 show_sys_state.php server sql injection (Advisory 132238 / EDB-37259)
10 months 3 weeks ago
A vulnerability was found in ISPConfig up to 3.0.5.4. It has been classified as critical. This affects an unknown part of the file monitor/show_sys_state.php. The manipulation of the argument server leads to sql injection.
This vulnerability is uniquely identified as CVE-2015-4118. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-32993 | SAML Single Sign On Plugin up to 2.0.2 on Jenkins certificate validation
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in SAML Single Sign On Plugin up to 2.0.2 on Jenkins. Affected is an unknown function. The manipulation leads to certificate with host mismatch.
This vulnerability is traded as CVE-2023-32993. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-32996 | SAML Single Sign On Plugin up to 2.0.0 on Jenkins HTTP POST Request permission
10 months 3 weeks ago
A vulnerability was found in SAML Single Sign On Plugin up to 2.0.0 on Jenkins. It has been classified as critical. This affects an unknown part of the component HTTP POST Request Handler. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2023-32996. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-30189 | posstaticblocks up to 1.0.0 on PrestaShop getPosCurrentHook sql injection
10 months 3 weeks ago
A vulnerability was found in posstaticblocks up to 1.0.0 on PrestaShop and classified as critical. This issue affects the function posstaticblocks::getPosCurrentHook. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2023-30189. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-32995 | SAML Single Sign On Plugin up to 2.0.0 on Jenkins HTTP POST Request cross-site request forgery
10 months 3 weeks ago
A vulnerability was found in SAML Single Sign On Plugin up to 2.0.0 on Jenkins. It has been classified as problematic. Affected is an unknown function of the component HTTP POST Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2023-32995. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-31679 | Videogo 6.8.1 Image Device Id access control
10 months 3 weeks ago
A vulnerability was found in Videogo 6.8.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument Device Id leads to improper access controls.
This vulnerability is handled as CVE-2023-31679. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-31678 | Videogo 6.8.1 access control
10 months 3 weeks ago
A vulnerability classified as critical has been found in Videogo 6.8.1. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2023-31678. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-31677 | luowice 3.5.18 eseeid permission
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in luowice 3.5.18. This issue affects some unknown processing. The manipulation of the argument eseeid leads to permission issues.
The identification of this vulnerability is CVE-2023-31677. The attack can only be done within the local network. There is no exploit available.
vuldb.com