Security
Headlines
HeadlinesLatestCVEs

Tag

#ssh

CVE-2023-2880: VDE-2023-011 | CERT@VDE

Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal vulnerability of the web interface by a crafted URL without authentication. This enables an remote attacker to read all files on the filesystem of the FDS001 device.

CVE
#vulnerability#web#mac#auth#ssh
Debian Security Advisory 5446-1

Debian Linux Security Advisory 5446-1 - It was discovered that Ghostscript, the GPL PostScript/PDF interpreter, does not properly handle permission validation for pipe devices, which could result in the execution of arbitrary commands if malformed document files are processed.

SSH Servers Hit in 'Proxyjacking' Cyberattacks

Cybercriminals employ obfuscated script to stealthily hijack victim server bandwidth for use in legitimate proxy networks.

Inout Search Engine AI Edition 1.1 Cross Site Scripting

Inout Search Engine AI Edition version 1.1 suffers from a cross site scripting vulnerability.

A proxyjacking campaign is looking for vulnerable SSH servers

Categories: Cybercrime Categories: News Tags: proxyjacking Tags: cryptojacking Tags: curl Tags: Docker Tags: proxy service Tags: compromised Proxyjacking is a cybercrime where your bandwidth is sold by criminals. (Read more...) The post A proxyjacking campaign is looking for vulnerable SSH servers appeared first on Malwarebytes Labs.

CVE-2023-35946: Fix dependency cache path traversal vulnerability · gradle/gradle@859eae2

Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle can be made to write files into an unintended location. The file may be written outside the dependency cache or over another file in the dependency cache. This vulnerability could be used to poison the dependency cache or overwrite important files elsewhere on the filesystem where the Gradle process has write permissions. Exploiting this vulnerability requires an attacker to have control over a dependency repository used by the Gradle build or have the ability to modify the build's configuration. It is unlikely that this would go unnoticed. A fix has been released in Gradle 7.6.2 and 8.2 to protect against this vulnerability. Gradle will refuse to cache dependencies that have path traversal elements in their depe...

GZ Multi Hotel Booking System 1.8 Cross Site Scripting

GZ Multi Hotel Booking System version 1.8 suffers from a cross site scripting vulnerability.

GZ E Learning Platform 1.8 Cross Site Scripting

GZ E Learning Platform version 1.8 suffers from a cross site scripting vulnerability.

CRM Platform 1.8 Cross Site Scripting

CRM Platform version 1.8 suffers from a cross site scripting vulnerability.

Property Listing Script 1.0 Cross Site Scripting

Property Listing Script version 1.0 suffers from a cross site scripting vulnerability.