Aggregator
CVE-2024-10810 | code-projects E-Health Care System 1.0 Doctor/app_request.php app_id sql injection
1 year 8 months ago
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the argument app_id with the input 1%27%20union%20select%20group_concat(table_name),database(),3,user(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20from%20information_schema.tables%20where%20table_schema=database()--+ as part of String leads to sql injection.
This vulnerability is traded as CVE-2024-10810. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10809 | code-projects E-Health Care System 1.0 /Doctor/chat.php name/message sql injection
1 year 8 months ago
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argument name/message leads to sql injection.
The identification of this vulnerability is CVE-2024-10809. The attack may be initiated remotely. Furthermore, there is an exploit available.
The initial researcher advisory only mentions the parameter "name" to be affected. But it must be assumed that the parameter "message" is affected as well.
vuldb.com
CVE-2024-10808 | code-projects E-Health Care System 1.0 Admin/req_detail.php id sql injection
1 year 8 months ago
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-10808. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
RansomHub
1 year 8 months ago
cohenido
RansomHub
1 year 8 months ago
cohenido
Red Hat security advisory (AV24-630)
1 year 8 months ago
Canadian Centre for Cyber Security
Randall Munroe’s XKCD ‘Disposal’
1 year 8 months ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Disposal’ appeared first on Security Boulevard.
Marc Handelman
CVE-2024-48336 | Magisk App prior 27007 ProviderInstaller.java install Local Privilege Escalation
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in Magisk App. This affects the function install of the file ProviderInstaller.java. The manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-48336. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #437018: code-projects E-Health Care System IN PHP v1.0 Easy SQL Injection [Accepted]
1 year 8 months ago
Submit #437018 / VDB-283038
moonose
Submit #436759: code-projects E-Health Care System IN PHP v1.0 SQL INJECTION [Accepted]
1 year 8 months ago
Submit #436759 / VDB-283037
Xueweian
Submit #436566: code-projects E-Health Care System IN PHP v1.0 SQL INJECTION [Accepted]
1 year 8 months ago
Submit #436566 / VDB-283036
Koevas
CVE-2024-51326 | projectworlds Travel Management System 1.0 deletesubcategory.php deletesubcategory t2 sql injection
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in projectworlds Travel Management System 1.0. Affected by this issue is the function deletesubcategory of the file deletesubcategory.php. The manipulation of the argument t2 leads to sql injection.
This vulnerability is handled as CVE-2024-51326. The attack may be launched remotely. There is no exploit available.
vuldb.com
更新3节:动态分析 | 看雪安卓高级研修班(月薪一万计划)
1 year 8 months ago
一起探索安卓逆向的奥秘
近100万台存在高危漏洞的 Fortinet、SonicWall 设备正暴露在公开网络中
1 year 8 months ago
SDC2024 议题回顾 | 从硬件钱包到TrustZone:Web3密钥托管的安全挑战与解决方案
1 year 8 months ago
剖析真实漏洞案例,融合开源方案实践
CVE-2024-51328 | projectworlds Travel Management System 1.0 addcategory.php t2 cross site scripting
1 year 8 months ago
A vulnerability classified as problematic was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file addcategory.php. The manipulation of the argument t2 leads to cross site scripting.
This vulnerability is known as CVE-2024-51328. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-51327 | projectworlds Travel Management System 1.0 loginform.php username/password sql injection
1 year 8 months ago
A vulnerability classified as critical has been found in projectworlds Travel Management System 1.0. Affected is an unknown function of the file loginform.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is traded as CVE-2024-51327. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
六年来首次停滞!网络安全就业市场提前入冬
1 year 8 months ago
德国大型药品批发商遭勒索攻击,欲扰乱超6000家药房供应
1 year 8 months ago
只能向药店提供有限范围的供货