Aggregator
共建新一代互联网生态 IPv6改造势在必行
1 year 8 months ago
IPv6规模部署的需求日益紧迫,但保障网络层安全是重要基础。
CVE-2007-6126 | project alumni up to 1.0.8 year cross site scripting (EDB-4655 / XFDB-38621)
1 year 8 months ago
A vulnerability classified as problematic has been found in project alumni up to 1.0.8. Affected is an unknown function. The manipulation of the argument year leads to cross site scripting.
This vulnerability is traded as CVE-2007-6126. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6127 | project alumni up to 1.0.8 view.page.inc.php year sql injection (EDB-4655 / XFDB-38620)
1 year 8 months ago
A vulnerability classified as critical was found in project alumni up to 1.0.8. Affected by this vulnerability is an unknown functionality of the file view.page.inc.php. The manipulation of the argument year leads to sql injection.
This vulnerability is known as CVE-2007-6127. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6128 | Flor De Utopia WorkingOnWeb 2.0.1400 events.php idevent sql injection (EDB-4653 / XFDB-38612)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Flor De Utopia WorkingOnWeb 2.0.1400. Affected by this issue is some unknown functionality of the file events.php. The manipulation of the argument idevent leads to sql injection.
This vulnerability is handled as CVE-2007-6128. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6217 | Irola My-Time 3.5 Login login.asp sql injection (EDB-4649 / BID-26548)
1 year 8 months ago
A vulnerability was found in Irola My-Time 3.5 and classified as critical. Affected by this issue is some unknown functionality of the file login.asp of the component Login. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2007-6217. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6129 | Amber Script 1.0 show_content.php id input validation (EDB-4652 / XFDB-38617)
1 year 8 months ago
A vulnerability, which was classified as critical, was found in Amber Script 1.0. This affects an unknown part of the file show_content.php. The manipulation of the argument id leads to improper input validation.
This vulnerability is uniquely identified as CVE-2007-6129. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6166 | Apple QuickTime up to 7.3 RTSP Content-Type Header memory corruption (EDB-6013 / Nessus ID 31383)
1 year 8 months ago
A vulnerability, which was classified as very critical, has been found in Apple QuickTime. Affected by this issue is some unknown functionality of the component RTSP Handler. The manipulation as part of Content-Type Header leads to memory corruption.
This vulnerability is handled as CVE-2007-6166. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to disable the affected component.
vuldb.com
CVE-2007-6139 | Mp3 ToolBox 1.0 Beta 5 index.php skin_file code injection (EDB-4650 / XFDB-38598)
1 year 8 months ago
A vulnerability was found in Mp3 ToolBox 1.0 Beta 5. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument skin_file leads to code injection.
This vulnerability was named CVE-2007-6139. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Microsoft发布2024年10月安全更新
1 year 8 months ago
10月9日,微软发布了2024年10月份的月度例行安全公告,修复了多款产品存在的117个安全漏洞
【漏洞通告】GitLab EE 权限绕过漏洞(CVE-2024-9164)
1 year 8 months ago
2024年10月10日,深瞳漏洞实验室监测到一则GitLab组件存在权限绕过漏洞的信息,漏洞编号:CVE-2024-9164,漏洞威胁等级:严重。
【漏洞通告】Mozilla Firefox Animation timelines远程代码执行漏洞(CVE-2024-9680)
1 year 8 months ago
2024年10月10日,深瞳漏洞实验室监测到一则Mozilla-firefox组件存在代码执行漏洞的信息,漏洞编号:CVE-2024-9680,漏洞威胁等级:严重。
Kingsoft × Hacking Group 议题征集,引领AI 安全新纪元!
1 year 8 months ago
安全KER小助手
豆包MarsCode合伙人计划限时招募中,推广最高赢万元现金
1 year 8 months ago
豆包MarsCode 合伙人计划正式上线啦!
字节跳动与清华 AIR 成立联合研究中心,推动大模型产学研合作
1 year 8 months ago
SIA Lab 旨在通过有效的产学研合作,实现大模型底层技术突破与产业应用构建。
GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks
1 year 8 months ago
A new tax-themed malware campaign targeting insurance and finance sectors has been observed leveraging GitHub links in phishing email messages as a way to bypass security measures and deliver Remcos RAT, indicating that the method is gaining traction among threat actors.
"In this campaign, legitimate repositories such as the open-source tax filing software, UsTaxes, HMRC, and InlandRevenue were
The Hacker News
CVE-2007-6137 | P3mbo Content Injector 1.52 news.php cat sql injection (EDB-4645 / XFDB-38627)
1 year 8 months ago
A vulnerability was found in P3mbo Content Injector 1.52 and classified as critical. Affected by this issue is some unknown functionality of the file news.php. The manipulation of the argument cat leads to sql injection.
This vulnerability is handled as CVE-2007-6137. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6134 | PHPKIT 1.6.4pl1 contentid sql injection (EDB-4646 / XFDB-38619)
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in PHPKIT 1.6.4pl1. This issue affects some unknown processing. The manipulation of the argument contentid leads to sql injection.
The identification of this vulnerability is CVE-2007-6134. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6176 | Amensa-Soft KB-Bestellsystem 2.3.3 kb_whois.cgi tld input validation (EDB-4647 / XFDB-38635)
1 year 8 months ago
A vulnerability was found in Amensa-Soft KB-Bestellsystem 2.3.3. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the file kb_whois.cgi. The manipulation of the argument tld leads to improper input validation.
This vulnerability is known as CVE-2007-6176. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-6133 | DevMass Devmass Cart up to 1.0 admin/kfm/initialise.php kfm_base_path input validation (EDB-4642 / XFDB-38609)
1 year 8 months ago
A vulnerability classified as critical was found in DevMass Devmass Cart up to 1.0. This vulnerability affects unknown code of the file admin/kfm/initialise.php. The manipulation of the argument kfm_base_path leads to improper input validation.
This vulnerability was named CVE-2007-6133. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com