🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-29468 ‼

A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30534 ‼

An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-32282 ‼

An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-32761 ‼

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30690 ‼

A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33149 ‼

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the CloneSite plugin, allowing an attacker to inject SQL by manipulating the url parameter.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-32777 ‼

An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerabilty is for the session cookie which can be leaked via JavaScript.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-2842 ‼

A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-206451.

📖 Read

via "National Vulnerability Database".
🕴 Metasploit Creator Renames His Startup and IT Discovery Tool Rumble 'runZero' 🕴

HD Moore's company has rebranded its IT, IoT, and OT asset discovery tool as the platform rapidly evolves.

📖 Read

via "Dark Reading".
‼ CVE-2021-29891 ‼

IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-38667 ‼

HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-38668 ‼

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive data from stack memory when fulfilling a request for a static file smaller than 16 KB.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-2923 ‼

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0239.

📖 Read

via "National Vulnerability Database".
🕴 Fake DDoS Protection Alerts Distribute Dangerous RAT 🕴

Security vendor Sucuri says adversaries are injecting malicious JavaScript into numerous WordPress websites that triggers phony bot-related checks.

📖 Read

via "Dark Reading".
🕴 Facing the New Security Challenges That Come With Cloud 🕴

Organizations relying on multicloud or hybrid-cloud environments without ďťża true understanding of their security vulnerabilities do so at their peril.

📖 Read

via "Dark Reading".
‼ CVE-2022-35191 ‼

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

📖 Read

via "National Vulnerability Database".
🤔1
‼ CVE-2022-2829 ‼

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

📖 Read

via "National Vulnerability Database".
‼ CVE-2019-25075 ‼

HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33916 ‼

OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-34919 ‼

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

📖 Read

via "National Vulnerability Database".
‼ CVE-2021-28861 ‼

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure.

📖 Read

via "National Vulnerability Database".