๐จ CVE-2021-38871
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208345.
๐@cveNotify
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208345.
๐@cveNotify
Ibmcloud
IBM Jazz Team Server cross-site scripting CVE-2021-38871 Vulnerability Report
IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers
๐จ CVE-2021-29865
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 206091.
๐@cveNotify
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 206091.
๐@cveNotify
Ibmcloud
IBM Jazz Team Server clickjacking CVE-2021-29865 Vulnerability Report
IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers
๐จ CVE-2021-41403
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
๐@cveNotify
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
๐@cveNotify
GitHub
Server-side request forgery vulnerability (SSRF) ยท Issue #60 ยท flatCore/flatCore-CMS
Describe the bug Server-side request forgery vulnerability (SSRF) To Reproduce Steps to reproduce the behavior: 1.go to 'acp/acp.php?tn=pages&sub=index' 2. Enter the intranet address in...
๐จ CVE-2022-31217
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
๐@cveNotify
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
๐@cveNotify
๐จ CVE-2022-31218
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
๐@cveNotify
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
๐@cveNotify
๐จ CVE-2022-31219
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
๐@cveNotify
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
๐@cveNotify
๐จ CVE-2022-21123
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
๐@cveNotify
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
๐@cveNotify
Intel
INTEL-SA-00615
๐จ CVE-2022-30154
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability.
๐@cveNotify
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability.
๐@cveNotify
๐จ CVE-2022-34059
The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
๐จ CVE-2022-34056
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
GitHub
code execution backdoor ยท Issue #1 ยท TimHessels/watertools
We found a malicious backdoor in versions 0.0.0 of this project, and its malicious backdoor is the request package. Even if the request package was removed by pypi, many mirror sites did not comple...
๐จ CVE-2022-34055
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
๐จ CVE-2022-34053
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
๐จ CVE-2022-33122
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.
๐@cveNotify
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.
๐@cveNotify
GitHub
There is stored XSS in version 1.5.6 which can lead to stealing sensitive information of logged-in users ยท Issue #24 ยท weng-xianhu/eyoucms
Software Link : https://github.com/eyoucms/eyoucms Website : http://www.eyoucms.com/ Vulnerable version 1.5.6 download address ๏ผhttps://www.eyoucms.com/plus/down.php After the installation is compl...
๐จ CVE-2022-33121
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
๐@cveNotify
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
๐@cveNotify
GitHub
There is CSRF vulnerabilities that can lead to deleting local .dat files ยท Issue #45 ยท bg5sbk/MiniCMS
Software Link : https://github.com/bg5sbk/MiniCMS After the installation is complete, log in as administrator, open the page In post.php, user can delete any local .dat files without filter Create ...
๐จ CVE-2022-32998
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
PyPI
cryptoasset-data-downloader
A desktop application to download historical data of desired crypto assets by connecting several different crypto-exchanges' API
๐จ CVE-2022-33002
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
PyPI
kgexplore
Python Package for Knowledge Exploration
๐จ CVE-2022-33003
The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
GitHub
code execution backdoor ยท Issue #5 ยท wateraccounting/watools
We found a malicious backdoor in versions 0.0.1~0.0.8 of this project, and its malicious backdoor is the request package. Even if the request package was removed by pypi, many mirror sites did not ...
๐จ CVE-2022-33001
The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
GitHub
code execution backdoor ยท Issue #1 ยท bOrionis/AAmiles
We found a malicious backdoor in versions 0.1.0 of this project, and its malicious backdoor is the request package. Even if the request package was removed by pypi, many mirror sites did not comple...
๐จ CVE-2022-33000
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
PyPI
ml-scanner
Scanner of ML publications
๐จ CVE-2022-32999
The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
GitHub
code execution backdoor ยท Issue #1 ยท SilvioGiancola/CloudLabeling-API
We found a malicious backdoor in version 0.0.1 of this project, and its malicious backdoor is the request package. Even if the request package was removed by pypi, many mirror sites did not complet...
๐จ CVE-2022-32997
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
๐@cveNotify
GitHub
code execution backdoor ยท Issue #206 ยท miranov25/RootInteractive
We found a malicious backdoor in versions 0.0.5~0.0.19b0 of this project, and its malicious backdoor is the request package. Even if the request package was removed by pypi, many mirror sites did n...