‼ CVE-2020-25472 ‼
📖 Read
via "National Vulnerability Database".
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-3985 ‼
📖 Read
via "National Vulnerability Database".
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orchestrator user may exploit an application weakness and call a vulnerable API to elevate their privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25473 ‼
📖 Read
via "National Vulnerability Database".
SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25474 ‼
📖 Read
via "National Vulnerability Database".
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-4000 ‼
📖 Read
via "National Vulnerability Database".
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is able to traversal directories which may lead to code execution of files.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25475 ‼
📖 Read
via "National Vulnerability Database".
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-3984 ‼
📖 Read
via "National Vulnerability Database".
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-4001 ‼
📖 Read
via "National Vulnerability Database".
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.📖 Read
via "National Vulnerability Database".
❌ Baidu Apps in Google Play Leak Sensitive Data ❌
📖 Read
via "Threat Post".
Cyberattackers could use the information to track users across devices, disable phone service, or intercept messages and phone calls.📖 Read
via "Threat Post".
Threat Post
Baidu Apps in Google Play Leak Sensitive Data
Cyberattackers could use the information to track users across devices, disable phone service, or intercept messages and phone calls.
❌ Smart Doorbells on Amazon, eBay, Harbor Serious Security Issues ❌
📖 Read
via "Threat Post".
Matt Lewis, with NCC Group, talks to Threatpost about a slew of security and privacy issues found in smart doorbells that are being sold on Amazon and eBay.📖 Read
via "Threat Post".
Threat Post
Smart Doorbells on Amazon, eBay, Harbor Serious Security Issues
Matt Lewis, with NCC Group, talks to Threatpost about a slew of security and privacy issues found in smart doorbells that are being sold on Amazon and eBay.
⚠ Gift card hack exposed – you pay, they play ⚠
📖 Read
via "Naked Security".
These crooks hacked into a network hoping to get everyone in the company to buy them gift cards.📖 Read
via "Naked Security".
Naked Security
Gift card hack exposed – you pay, they play
These crooks hacked into a network hoping to get everyone in the company to buy them gift cards.
🔏 FBI Warns of Spoofed FBI Websites 🔏
📖 Read
via "Digital Guardian".
The FBI is urging the American public to ensure they're getting "reliable and verified FBI information."📖 Read
via "Digital Guardian".
Digital Guardian
FBI Warns of Spoofed FBI Websites
The FBI is urging the American public to ensure they're getting "reliable and verified FBI information."
🕴 US Treasury's OFAC Ransomware Advisory: Navigating the Gray Areas 🕴
📖 Read
via "Dark Reading".
Leveraging the right response strategy, following the regulations, and understanding the ransom entity are the fundamentals in any ransomware outbreak.📖 Read
via "Dark Reading".
Dark Reading
US Treasury's OFAC Ransomware Advisory: Navigating the Gray Areas
Leveraging the right response strategy, following the regulations, and understanding the ransom entity are the fundamentals in any ransomware outbreak.
🕴 What's in Store for Privacy in 2021 🕴
📖 Read
via "Dark Reading".
Changes are coming to the privacy landscape, including more regulations and technologies.📖 Read
via "Dark Reading".
Dark Reading
What's in Store for Privacy in 2021
Changes are coming to the privacy landscape, including more regulations and technologies.
‼ CVE-2020-13620 ‼
📖 Read
via "National Vulnerability Database".
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28994 ‼
📖 Read
via "National Vulnerability Database".
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-7378 ‼
📖 Read
via "National Vulnerability Database".
CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was resolved in version 5.0-20200904, released September 4, 2020.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29040 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error. NOTE: this issue is caused by an incorrect fix for CVE-2020-27671.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-13942 ‼
📖 Read
via "National Vulnerability Database".
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-24815 ‼
📖 Read
via "National Vulnerability Database".
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded in a dossier/dashboard document. NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28331 ‼
📖 Read
via "National Vulnerability Database".
Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemon included in the firmware image. By default, the SSH daemon is disabled and does not start at system boot. The system initialization scripts read a device configuration file variable to see if the SSH daemon should be started. The web interface does not provide a visible capability to alter this configuration file variable. However, a malicious actor can include this variable in a POST such that the SSH daemon will be started when the device boots.📖 Read
via "National Vulnerability Database".