Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-26563: File system provider in EJ2 TypeScript File manager control

The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file, download any directory, delete any file, upload any file to any directory accessible by the web server.

CVE
#sql#web#windows#google#amazon#linux#nodejs#js#git#aws#oauth#auth#ibm#asp.net
New Attack Drops LokiBot Malware Via Malicious Macros in Word Docs

By Waqas LokiBot, a notorious Trojan active since 2015, specializes in stealing sensitive information from Windows machines, posing a significant threat to user data. This is a post from HackRead.com Read the original post: New Attack Drops LokiBot Malware Via Malicious Macros in Word Docs

Chinese Group Storm-0558 Hacked European Govt Emails, Microsoft

By Waqas Microsoft has exposed and halted an intrusion campaign by a China-based threat actor, Storm-0558. This is a post from HackRead.com Read the original post: Chinese Group Storm-0558 Hacked European Govt Emails, Microsoft

CVE-2023-29308: Adobe Security Bulletin

Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Banner RotatorCMS 1.0 Database Disclosure

Banner RotatorCMS version 1.0 suffers from a database disclosure vulnerability.

Avidi Media 2.0 Insecure Settings

Avidi Media version 2.0 appears to leave default credentials installed after installation.

AtTestimonials CMS 1.2 Missing Authentication

AtTestimonials CMS version 1.2 suffers from a missing authentication vulnerability.

Atom CMS 2.0 Directory Traversal

Atom CMS version 2.0 suffers from a directory traversal vulnerability.

Nedal CMS 1.2 SQL Injection

Nedal CMS version 1.2 suffers from a remote SQL injection vulnerability.

Asanhamayesh CMS 3.4.6 Directory Traversal

Asanhamayesh CMS version 3.4.6 suffers from a directory traversal vulnerability.