Tag
#windows
Student Enrollment version 1.0 suffers from an arbitrary file upload vulnerability.
Sistem Penyewaan Baju atau Pakaian Berbasis Web version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Simple Student Quarterly Result / Grade System version 1.0 suffers from an ignored default credential vulnerability.
Simple Responsive Tourism Website version 1.0 suffers from a cross site request forgery vulnerability.
Simple Music Management System version 1.0 suffers from add administrator and cross site request forgery vulnerabilities.
Sample Blog Site version 1.0 suffers from cross site scripting and remote file inclusion vulnerabilities.
Backdoor.Win32.Benju.a malware suffers from a remote command execution vulnerability. This is the 700th release of a malvuln finding.
Adversaries can exploit CVE-2024-6769 to jump from regular to admin access without triggering UAC, but Microsoft says it's not really a vulnerability.
Simple Online Banking System version 1.0 suffers from an ignored default credential vulnerability.
### Impact A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL. SUSE is unaware of any successful exploitation of this vulnerability, which has a high complexity bar. Please consult the associated [MITRE ATT&CK - Technique - Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557/) for further information about this attack category. ### Patches A new setting, [`agent-tls-mode`](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/installation-references/tls-settings), was added, which allows users to specify if agents will use `strict` certificate verification when connecting to Rancher. The field can be set to `strict` (which requires the agent to ver...