βΌ CVE-2020-11720 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this password.π Read
via "National Vulnerability Database".
βΌ CVE-2020-11718 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.π Read
via "National Vulnerability Database".
βΌ CVE-2020-35586 βΌ
π Read
via "National Vulnerability Database".
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).π Read
via "National Vulnerability Database".
βΌ CVE-2020-25198 βΌ
π Read
via "National Vulnerability Database".
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the userΓ’β¬β’s cookies.π Read
via "National Vulnerability Database".
βΌ CVE-2020-29551 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _internal/pc/vpro.php, _internal/pc/wake.php, _internal/error_u201409.txt, _internal/runcmd.php, _internal/getConfiguration.php, ews/autoload.php, ews/del.php, ews/mod.php, ews/sync.php, utils/backup/backup_server.php, utils/backup/restore_server.php, MyScreens/timeline.config, kreator.html5/test.php, and addedlogs.txt.π Read
via "National Vulnerability Database".
βΌ CVE-2020-35650 βΌ
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the ulgm_user_last POST Parameter in user-registration-form.php, the ulgm_user_email POST Parameter in user-registration-form.php, the ulgm_code_registration POST Parameter in user-registration-form.php, the ulgm_terms_conditions POST Parameter in user-registration-form.php, the _ulgm_total_seats POST Parameter in frontend-uo_groups_buy_courses.php, the uncanny_group_signup_user_first POST Parameter in group-registration-form.php, the uncanny_group_signup_user_last POST Parameter in group-registration-form.php, the uncanny_group_signup_user_login POST Parameter in group-registration-form.php, the uncanny_group_signup_user_email POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uo_groups.php, the bulk-errors GET Parameter in frontend-uo_groups.php, or the message GET Parameter in frontend-uo_groups.php.π Read
via "National Vulnerability Database".
βΌ CVE-2020-25194 βΌ
π Read
via "National Vulnerability Database".
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2020-29552 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.π Read
via "National Vulnerability Database".
βΌ CVE-2020-25196 βΌ
π Read
via "National Vulnerability Database".
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.π Read
via "National Vulnerability Database".
π΄ Lazarus Group Seeks Intelligence Related to COVID-19 π΄
π Read
via "Dark Reading".
Researchers attribute attacks targeting a pharmaceutical company and a government ministry related to COVID-19 response.π Read
via "Dark Reading".
Dark Reading
Lazarus Group Seeks Intelligence Related to COVID-19
Researchers attribute attacks targeting a pharmaceutical company and a government ministry related to COVID-19 response.
β Lazarus Group Hits COVID-19 Vaccine-Maker in Espionage Attack β
π Read
via "Threat Post".
The nation-state actor is looking to speed up vaccine development efforts in North Korea.π Read
via "Threat Post".
Threat Post
Lazarus Group Hits COVID-19 Vaccine-Maker in Espionage Attack
The nation-state actor is looking to speed up vaccine development efforts in North Korea.
π¦Ώ 6 persuasion tactics used in social engineering attacks π¦Ώ
π Read
via "Tech Republic".
IT security teams need to educate employees about the psychological techniques cybercriminals often use in social engineering attacks.π Read
via "Tech Republic".
TechRepublic
6 persuasion tactics used in social engineering attacks
IT security teams need to educate employees about the psychological techniques cybercriminals often use in social engineering attacks.
βΌ CVE-2020-28073 βΌ
π Read
via "National Vulnerability Database".
SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.π Read
via "National Vulnerability Database".
βΌ CVE-2020-27397 βΌ
π Read
via "National Vulnerability Database".
Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2020-28071 βΌ
π Read
via "National Vulnerability Database".
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.π Read
via "National Vulnerability Database".
βΌ CVE-2020-11719 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4642 βΌ
π Read
via "National Vulnerability Database".
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".π Read
via "National Vulnerability Database".
βΌ CVE-2018-1000891 βΌ
π Read
via "National Vulnerability Database".
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.π Read
via "National Vulnerability Database".
βΌ CVE-2020-28074 βΌ
π Read
via "National Vulnerability Database".
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.π Read
via "National Vulnerability Database".
βΌ CVE-2018-1000893 βΌ
π Read
via "National Vulnerability Database".
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.π Read
via "National Vulnerability Database".
βΌ CVE-2020-13969 βΌ
π Read
via "National Vulnerability Database".
CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.π Read
via "National Vulnerability Database".