Aggregator
绕过限制:若依模板注入在高版本 Thymeleaf 中的绕过分析
8 months 3 weeks ago
绕过限制:若依模板注入在高版本 Thymeleaf 中的绕过分析
CVE-2017-20197 | propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c /includes/login.php Username sql injection
8 months 3 weeks ago
A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection.
This vulnerability was named CVE-2017-20197. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
北美大陆底部岩石在滴落
8 months 3 weeks ago
德州奥斯丁的地球科学家报告,北美大陆底部岩石块正在滴落,地幔中下沉的板块残余被认为造成这一现象的原因。这种现象被称为“克拉通变薄”。克拉通(Cratons)又被称为稳定地块或安定地块,是大陆地壳上的古老而稳定的部分,于最近至少 5 亿年内的大陆和超大陆的会聚和分裂过程中几乎没有发生变化。但克拉通有时也会发生变化,影响其稳定性或者移除整个岩层。例如中国华北地区的克拉通地块在数百万年前失去了其最深处的根层。北美的岩石块滴落现象集中在美国中西部,研究人员表示不必要担心大陆会被掏空或滴落会改变地貌,因为整个过程是非常缓慢的,而且随着板块残余沉入地幔深处,对克拉通的影响会减弱,滴落现象最终将会停止。
PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks
8 months 3 weeks ago
A malicious campaign dubbed PoisonSeed is leveraging compromised credentials associated with customer relationship management (CRM) tools and bulk email providers to send spam messages containing cryptocurrency seed phrases in an attempt to drain victims' digital wallets.
"Recipients of the bulk spam are targeted with a cryptocurrency seed phrase poisoning attack," Silent Push said in an
The Hacker News
CVE-2024-28909 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability was found in Microsoft OLE DB Driver and SQL Server. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-28909. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28910 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability was found in Microsoft OLE DB Driver and SQL Server. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-28910. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28911 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability classified as critical has been found in Microsoft OLE DB Driver and SQL Server. This affects an unknown part. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-28911. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28912 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability classified as critical was found in Microsoft OLE DB Driver and SQL Server. This vulnerability affects unknown code. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-28912. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28913 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Microsoft OLE DB Driver and SQL Server. This issue affects some unknown processing. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-28913. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28914 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft OLE DB Driver and SQL Server. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-28914. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28915 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability has been found in Microsoft OLE DB Driver and SQL Server and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2024-28915. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-28925 | Microsoft Windows up to Server 2022 23H2 Secure Boot stack-based overflow
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. This affects an unknown part of the component Secure Boot. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-28925. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-3393 | mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509 Personal Settings Interface /ucan-admin/index cross site scripting (IBT2W5)
8 months 3 weeks ago
A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been classified as problematic. This affects an unknown part of the file /ucan-admin/index of the component Personal Settings Interface. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-3393. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
vuldb.com
CVE-2025-3392 | hailey888 oa_system up to 2025.01.01 Backend MailController.java save MailNumberId cross site scripting (IBRQZ9)
8 months 3 weeks ago
A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file cn/gson/oasys/controller/mail/MailController.java of the component Backend. The manipulation of the argument MailNumberId leads to cross site scripting.
This vulnerability is handled as CVE-2025-3392. The attack may be launched remotely. Furthermore, there is an exploit available.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
vuldb.com
CVE-2025-3391 | hailey888 oa_system up to 2025.01.01 Backend AddrController. java outAddress outtype cross site scripting (IBRRX3)
8 months 3 weeks ago
A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the file cn/gson/oass/controller/address/AddrController. java of the component Backend. The manipulation of the argument outtype leads to cross site scripting.
This vulnerability is known as CVE-2025-3391. The attack can be launched remotely. Furthermore, there is an exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
vuldb.com
CVE-2025-3390 | hailey888 oa_system up to 2025.01.01 Backend DaymanageController.java addandchangeday scheduleList cross site scripting (IBRRZX)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Backend. The manipulation of the argument scheduleList leads to cross site scripting.
This vulnerability is traded as CVE-2025-3390. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
vuldb.com
CVE-2025-3389 | hailey888 oa_system up to 2025.01.01 Backend InformManageController.java testMess menu cross site scripting (IBRQXH)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to cross site scripting.
The identification of this vulnerability is CVE-2025-3389. The attack may be initiated remotely. Furthermore, there is an exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
vuldb.com
CVE-2025-3388 | hailey888 oa_system up to 2025.01.01 Frontend LoginsController.java loginCheck Username cross site scripting (IBRQYI)
8 months 3 weeks ago
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting.
This vulnerability was named CVE-2025-3388. The attack can be initiated remotely. Furthermore, there is an exploit available.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
vuldb.com
CVE-2024-28926 | Microsoft OLE DB Driver/SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability has been found in Microsoft OLE DB Driver and SQL Server and classified as critical. This vulnerability affects unknown code. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-28926. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com