πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-41763 β€Ό

An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ As LotL Attacks Evolve, So Must Defenses πŸ•΄

Because living-off-the-land (LotL) attacks masquerade as frequently used, legitimate companies, they are very difficult to block and detect.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-32086 β€Ό

** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2453 β€Ό

There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a Γ’β‚¬Λœrequire_onceÒ€ℒ statement. This allows arbitrary files with the Γ’β‚¬Λœ.phpÒ€ℒ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a Γ’β‚¬Λœ.phpÒ€ℒ file payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4480 β€Ό

Due to an out-of-date dependency in the Ò€œFusion File ManagerҀ� component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the privileges of the running process. Additionally, they may write files to arbitrary locations, provided the files pass the applicationÒ€ℒs mime-type and file extension validation.Γ‚ 

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40743 β€Ό

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE.As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this problem, though contributors that would like to work towards this are welcome.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Companies Can Cope With the Risks of Generative AI Tools πŸ•΄

To benefit from AI yet minimize risk, companies should be cautious about information they share, be aware of AI's limitations, and stay vigilant about business implications.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-35124 β€Ό

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41108 β€Ό

TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32615 β€Ό

A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41107 β€Ό

TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34998 β€Ό

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36361 β€Ό

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32271 β€Ό

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34353 β€Ό

An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3374 β€Ό

Incomplete List of Disallowed Inputs vulnerability in Bookreen allows Privilege Escalation.This issue affects Bookreen: before 3.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41012 β€Ό

An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4778 β€Ό

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3375 β€Ό

Unrestricted Upload of File with Dangerous Type vulnerability in Bookreen allows OS Command Injection.This issue affects Bookreen: before 3.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31242 β€Ό

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34994 β€Ό

An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directory. An attacker can send a sequence of requests to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".