Tag
#auth
Creating a new office of cyber-regulation strategy is the government's best opportunity to improve security and to protect Americans in an increasingly dangerous world.
ABB Cylon Aspect versions 3.08.00 and below suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the timeserver HTTP POST parameter called by the setTimeServer.php script.
ABB Cylon Aspect versions 3.08.01 and below suffer from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the logFile GET parameter via the logYumLookup.php script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
ManageEngine ADManager Plus builds prior to 7210 suffers from a privilege escalation vulnerability.
Book Recording App, as submitted on 2024-09-24, suffers from a persistent cross site scripting vulnerability.
Debian Linux Security Advisory 5785-1 - Dom Walden discovered that the AbuseFilter extension in MediaWiki, a website engine for collaborative work, performed incomplete authorisation checks.
OpenMediaVault version 7.4.2-2 suffers from a PHP code injection vulnerability.
Netis MW5360 suffers from a PHP code injection vulnerability.
Hikvision IP Cameras suffer from a cross site request forgery vulnerability.
GeoServer version 2.25.1 suffers from a PHP code injection vulnerability.