Aggregator
Submit #430029: SourceCodester Petrol Pump Management Software 1.0 Unrestricted Upload [Duplicate]
8 months 3 weeks ago
Submit #430029 / VDB-255456
K1nako
JetBrains Rider 和 WebStorm 允许非商业用户免费使用
8 months 3 weeks ago
捷克的软件开发商 JetBrains 宣布,用于.NET 开发、以及 Unity (C#) 和 Unreal Engine (C++)游戏开发的 IDE Rider 和 Web, JavaScript 和 TypeScript 的 IDE WebStorm 允许非商业用户免费使用。JetBrains 称,今年早些时候,IDE RustRover 和 Aqua 实施了一种新的许可模式,即面向非商业用途免费提供。现在这一模式扩展到 WebStorm 和 Rider。如果用户将这些 IDE 用于非商业用途,例如学习、开源项目开发、内容创建或业余爱好开发,那么现在可以免费使用这些 IDE。这项变动不涉及商业项目,它将继续实施现有的许可模式。其他 JetBrains IDE 也不受此更新的影响。它将根据效果判断是否可以推广带其它 IDE。
CVE-2024-10351 | Tenda RX9 Pro 22.03.02.20 POST Request /goform/setMacFilterCfg sub_424CE0 deviceList stack-based overflow
8 months 3 weeks ago
A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-10351. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #427957: Sourcecodester Online Exam system using Django V 1.0 Improper Access Controls [Accepted]
8 months 3 weeks ago
Submit #427957 / VDB-281700
TheRaghul
CVE-2024-10350 | code-projects Hospital Management System 1.0 /admin/add-doctor.php docname sql injection
8 months 3 weeks ago
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection.
This vulnerability was named CVE-2024-10350. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
msldap:一款用于审计MS AD的LDAP库
8 months 3 weeks ago
msldap是一款用于审计MS AD的LDAP库,广大研究人员可以利用该工具轻松执行针对MS AD的安全审计任务。
Submit #427706: Tenda Rx9 Router RX9 Pro Firmware V22.03.02.20 Stack-based Buffer Overflow [Accepted]
8 months 3 weeks ago
Submit #427706 / VDB-281699
GuoXB
Submit #427705: code-projects Responsive Hotel Site Using PHP 1.0 sql [Accepted]
8 months 3 weeks ago
Submit #427705 / VDB-281698
R7Shell
hnb659fds: опасная привычка, ставшая ключом для доступа к AWS
8 months 3 weeks ago
Обычное упущение послужило отправной точкой для масштабных атак.
Perfctl 恶意软件再度来袭,加密骗子瞄准 Docker 远程 API 服务器
8 months 3 weeks ago
安全客
CVE-2024-10348 | SourceCodester Best House Rental Management System 1.0 Manage Tenant Details /index.php?page=tenants Last Name/First Name/Middle Name cross site scripting
8 months 3 weeks ago
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the component Manage Tenant Details. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10348. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The initial researcher advisory only shows the field "Last Name" to be affected. Other fields might be affected as well.
vuldb.com
CVE-2024-10349 | SourceCodester Best House Rental Management System 1.0 ajax.php?action=delete_tenant id sql injection
8 months 3 weeks ago
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected by this issue is the function delete_tenant of the file /ajax.php?action=delete_tenant. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2024-10349. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
新的 Grandoreiro 银行恶意软件变种出现,采用先进策略躲避检测
8 months 3 weeks ago
安全客
Submit #427471: https://www.sourcecodester.com/php/17375/best-courier-management house rental management system 1 Stored Cross-Site Scripting [Accepted]
8 months 3 weeks ago
Submit #427471 / VDB-281697
willdone1
Submit #427472: https://www.sourcecodester.com/php/17375/best-courier-management house rental management system 1 SQL Injection [Accepted]
8 months 3 weeks ago
Submit #427472 / VDB-281696
willdone1
挪威将青少年使用社交网络的最低年龄提高到 15 岁
8 months 3 weeks ago
挪威计划严格执行社交网络最低年龄 15 岁的政策,以保护青少年免受社交网络有害内容和算法的影响。目前使用社交网络的最低年龄是 13 岁。但现实中年龄低于 13 岁的儿童已经在大量使用社交媒体,根据 Norwegian Media Authority 的研究,超过半数的 9 岁儿童、58% 的 10 岁儿童和 72% 的 11 岁儿童已在使用社交媒体。政府承诺采取更多保护措施防止儿童绕过年龄限制,包括修改《Personal Data Act》,要求社交媒体用户必须年满 15 岁才能同意平台处理其个人数据,它正在为社交媒体开发年龄验证屏障。挪威首相周三表示,此举发出了一个强有力的信号,必须保护儿童免受社交媒体有害内容的侵害。这是大型科技巨头与幼儿大脑的较量。这将是一场艰苦的战斗,这也是需要政治的地方。
New Qilin ransomware encryptor features stronger encryption, evasion
8 months 3 weeks ago
A new Rust-based variant of the Qilin (Agenda) ransomware strain, dubbed 'Qilin.B,' has been spotted in the wild, featuring stronger encryption, better evasion from security tools, and the ability to disrupt data recovery mechanisms. [...]
Bill Toulas
Cisco ASA, FTD Software Under Active VPN Exploitation
8 months 3 weeks ago
Unauthenticated threat actors can remotely cause a denial-of-service (DoS) cyberattack within the Remote Access VPN software in Cisco's ASA and Firepower software.
Dark Reading Staff
DeTankZone: хакеры превратили онлайн-игру в оружие для кражи криптовалюты
8 months 3 weeks ago
Как 0day-уязвимость в Chrome стала ключом к чужим богатствам.