โผ CVE-2022-44808 โผ
๐ Read
via "National Vulnerability Database".
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-44184 โผ
๐ Read
via "National Vulnerability Database".
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.๐ Read
via "National Vulnerability Database".
โ How to hack an unpatched Exchange server with rogue PowerShell code โ
๐ Read
via "Naked Security".
Review your servers, your patches and your authentication policies - there's a proof-of-concept out๐ Read
via "Naked Security".
Sophos News
Naked Security โ Sophos News
๐ด Cyber Due Diligence in M&As Uncovers Threats, Improves Valuations ๐ด
๐ Read
via "Dark Reading".
To get the full picture, companies need to look into the cybersecurity history and practices of the business they're acquiring.๐ Read
via "Dark Reading".
Dark Reading
Cyber Due Diligence in M&As Uncovers Threats, Improves Valuations
To get the full picture, companies need to look into the cybersecurity history and practices of the business they're acquiring.
๐ด How Work From Home Shaped the Road to SASE for Enterprises ๐ด
๐ Read
via "Dark Reading".
As SASE adoption grows, with its allure of simplified protection via one network and security experience for hybrid workers, remember: Have an overall plan, integrate and migrate to scale usage, and start small.๐ Read
via "Dark Reading".
Dark Reading
How Work From Home Shaped the Road to SASE for Enterprises
As SASE adoption grows, with its allure of simplified protection via one network and security experience for hybrid workers, remember: Have an overall plan, integrate and migrate to scale usage, and start small.
โผ CVE-2022-39067 โผ
๐ Read
via "National Vulnerability Database".
There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41950 โผ
๐ Read
via "National Vulnerability Database".
super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-39070 โผ
๐ Read
via "National Vulnerability Database".
There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43212 โผ
๐ Read
via "National Vulnerability Database".
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-39066 โผ
๐ Read
via "National Vulnerability Database".
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.๐ Read
via "National Vulnerability Database".
๐ด DraftKings Account Takeovers Frame Sports-Betting Cybersecurity Dilemma ๐ด
๐ Read
via "Dark Reading".
Cybercrooks have drained DraftKings accounts of $300K in the past few days thanks to credential stuffing, just as the 2022 FIFA World Cup starts up.๐ Read
via "Dark Reading".
Dark Reading
DraftKings Account Takeovers Frame Sports-Betting Cybersecurity Dilemma
Cybercrooks have drained DraftKings accounts of $300K in the past few days thanks to credential stuffing, just as the 2022 FIFA World Cup starts up.
โผ CVE-2022-41919 โผ
๐ Read
via "National Vulnerability Database".
Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch()` requests with Content-Typeรยขรขโยฌรขโยขs essence as "application/x-www-form-urlencoded", "multipart/form-data", or "text/plain", could potentially be used to invoke routes that only accepts `application/json` content type, thus bypassing any CORS protection, and therefore they could lead to a Cross-Site Request Forgery attack. This issue has been patched in version 4.10.2 and 3.29.4. As a workaround, implement Cross-Site Request Forgery protection using `@fastify/csrf'.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40228 โผ
๐ Read
via "National Vulnerability Database".
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235527.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-4116 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-2791 โผ
๐ Read
via "National Vulnerability Database".
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41942 โผ
๐ Read
via "National Vulnerability Database".
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send a crafted request to gitserver that would execute commands inside the container. Successful exploitation requires the ability to send local requests to gitserver. The issue is patched in version 4.1.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41943 โผ
๐ Read
via "National Vulnerability Database".
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-3500 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-39199 โผ
๐ Read
via "National Vulnerability Database".
immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. SDK does not validate this uuid and can accept any value reported by the server. A malicious server can change the reported UUID tricking the client to treat it as a different server thus accepting a state completely irrelevant to the one previously retrieved from the server. This issue has been patched in version 1.4.1. As a workaround, when initializing an immudb client object a custom state handler can be used to store the state. Providing custom implementation that ignores the server UUID can be used to ensure that even if the server changes the UUID, client will still consider it to be the same server.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-39397 โผ
๐ Read
via "National Vulnerability Database".
aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45330 โผ
๐ Read
via "National Vulnerability Database".
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.๐ Read
via "National Vulnerability Database".