Aggregator
李彦宏将做 AI 主题演讲;福特 CEO 爱开小米 SU7 被美国网友怒喷;前员工黑进迪士尼乐园,菜单里加脏话 | 极客早知道
1 year 8 months ago
波士顿动力人形机器人已进厂打工;马斯克计划为 xAI 从中东募资;谷歌被俄罗斯罚款 35 位数。
科技爱好者周刊(第 323 期):技术公司的口号比拼
1 year 8 months ago
Qilin
1 year 8 months ago
cohenido
威努特亮相上汽集团新赛道技术创新高峰论坛,打造智能网联汽车安全新生态
1 year 8 months ago
科技驱动,创新引领。
CVE-2024-10607 | code-projects Courier Management System 1.0 /track-result.php Consignment sql injection
1 year 8 months ago
A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. The manipulation of the argument Consignment leads to sql injection.
This vulnerability was named CVE-2024-10607. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10608 | code-projects Courier Management System 1.0 /login.php txtusername sql injection
1 year 8 months ago
A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection.
The identification of this vulnerability is CVE-2024-10608. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10609 | itsourcecode Tailoring Management System Project 1.0 typeadd.php sex sql injection
1 year 8 months ago
A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. The manipulation of the argument sex leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10609. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10610 | ESAFENET CDG 5 ProtocolService.java delProtocol id sql injection
1 year 8 months ago
A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-10610. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10611 | ESAFENET CDG 5 PrintScreenListService.java delProtocol id sql injection
1 year 8 months ago
A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2024-10611. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10612 | ESAFENET CDG 5 HookInvalidCourseService.java removeHookInvalidCourse id sql injection
1 year 8 months ago
A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2024-10612. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10613 | ESAFENET CDG 5 SystemEncryptPolicyService.java delSystemEncryptPolicy id sql injection
1 year 8 months ago
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/system/SystemEncryptPolicyService.java. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2024-10613. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-10615 | Tongda OA 2017 up to 11.10 delete_data_attach.php RUN_ID sql injection
1 year 8 months ago
A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/query/list/input_form/delete_data_attach.php. The manipulation of the argument RUN_ID leads to sql injection.
This vulnerability is handled as CVE-2024-10615. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Нулевая активность при полной загрузке: новый баг Windows 11
1 year 8 months ago
Ошибка затронула пользователей последней версии 24H2.
CVE-2010-3682 | MySQL up to 5.1.25 store null pointer dereference (Bug 628328 / EDB-34506)
1 year 8 months ago
A vulnerability was found in MySQL up to 5.1.25. It has been rated as problematic. Affected by this issue is the function Item_singlerow_subselect::store. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2010-3682. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
MSSprinkler:一款针对MS账号的密码喷射安全测试工具
1 year 8 months ago
MSSprinkler是一款功能强大的密码喷射安全测试工具,可以帮助广大研究人员从外部角度测试其 Microsoft Online 帐户的安全性。
CVE-2024-48735 | SAS Studio 9.4 {InternalPath} path traversal
1 year 8 months ago
A vulnerability has been found in SAS Studio 9.4 and classified as critical. This vulnerability affects unknown code of the file /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath}. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-48735. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-48346 | xtreme1 up to 0.9.1 /api/data/upload fileUrl server-side request forgery (Issue 284)
1 year 8 months ago
A vulnerability classified as critical was found in xtreme1 up to 0.9.1. This vulnerability affects unknown code of the file /api/data/upload. The manipulation of the argument fileUrl leads to server-side request forgery.
This vulnerability was named CVE-2024-48346. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-51259 | DrayTek Vigor 3900 1.5.1.3 mainfunction.cgi setup_cacertificate command injection
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in DrayTek Vigor 3900 1.5.1.3. Affected by this issue is the function setup_cacertificate of the file mainfunction.cgi. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-51259. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-10594 | ESAFENET CDG 5 FileDirectoryService.java docHistory fileId sql injection
1 year 8 months ago
A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument fileId leads to sql injection.
This vulnerability is traded as CVE-2024-10594. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com