βΌ CVE-2022-26479 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2016-15003 βΌ
π Read
via "National Vulnerability Database".
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33891 βΌ
π Read
via "National Vulnerability Database".
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.π Read
via "National Vulnerability Database".
β 7 cybersecurity tips for your summer vacation! β
π Read
via "Naked Security".
Here you go - seven thoughtful cybersecurity tips to help you travel safely...π Read
via "Naked Security".
Naked Security
7 cybersecurity tips for your summer vacation!
Here you go β seven thoughtful cybersecurity tips to help you travel safelyβ¦
β CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2 β
π Read
via "Threat Post".
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.π Read
via "Threat Post".
Threat Post
CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.
β Google Boots Multiple Malware-laced Android Apps from Marketplace β
π Read
via "Threat Post".
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.π Read
via "Threat Post".
Threat Post
Google Boots Multiple Malware-laced Android Apps from Marketplace
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.
ποΈ Prototype pollution in Blitz.js leads to remote code execution ποΈ
π Read
via "The Daily Swig".
Chain of exploits could be triggered without any authenticationπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Prototype pollution in Blitz.js leads to remote code execution
Chain of exploits could be triggered without any authentication
π΄ Watch Out for User Impersonation in Low-Code/No-Code Apps π΄
π Read
via "Dark Reading".
How a well-meaning employee could unwittingly share their identity with other users, causing a whole range of problems across IT, security, and the business.π Read
via "Dark Reading".
Dark Reading
Watch Out for User Impersonation in Low-Code/No-Code Apps
How a well-meaning employee could unwittingly share their identity with other users, causing a whole range of problems across IT, security, and the business.
ποΈ βEndemicβ Log4j bug set to persist in the wild for at least a decade, US government warns ποΈ
π Read
via "The Daily Swig".
Inaugural report from cyber safety panel outlines strengths and weaknesses exposed by momentous security flawπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
βEndemicβ Log4j bug set to persist in the wild for at least a decade, US government warns
Inaugural report from cyber safety panel outlines strengths and weaknesses exposed by momentous security flaw
βΌ CVE-2022-30625 βΌ
π Read
via "National Vulnerability Database".
Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24689 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being authenticated. The collected information includes the badge numbers that operate as user login names. They have a PIN code. The PIN code is 4 digits and thus can be guessed in 10000 brute force attempts.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30621 βΌ
π Read
via "National Vulnerability Database".
Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30623 βΌ
π Read
via "National Vulnerability Database".
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24692 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the final goal of achieving client-side code execution.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-30620 βΌ
π Read
via "National Vulnerability Database".
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30624 βΌ
π Read
via "National Vulnerability Database".
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24691 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30627 βΌ
π Read
via "National Vulnerability Database".
This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the existing user passwords on their operating systems and passwords.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24690 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An unauthenticated attacker can discover the endpoint by abusing a Broken Access Control issue with further SQL injection attacks to gather all user's badge numbers and PIN codes.)π Read
via "National Vulnerability Database".
βΌ CVE-2022-24688 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the Parameters page in order to exploit this issue. (That can be easily achieved by exploiting the Broken Access Control with further Brute-force attack or SQL Injection.) The uploaded file is stored within the database and copied to the sync web folder if the attacker visits a certain .php?action= page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30626 βΌ
π Read
via "National Vulnerability Database".
Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.π Read
via "National Vulnerability Database".