Tag
#windows
A list of topics we covered in the week of August 12 to August 18 of 2024
A newly patched security flaw in Microsoft Windows was exploited as a zero-day by Lazarus Group, a prolific state-sponsored actor affiliated with North Korea. The security vulnerability, tracked as CVE-2024-38193 (CVSS score: 7.8), has been described as a privilege escalation bug in the Windows Ancillary Function Driver (AFD.sys) for WinSock. "An attacker who successfully exploited this
Build Your Own Botnet (BYOB) version 2.0.0 exploit that works by spoofing an agent callback to overwrite the sqlite database and bypass authentication and exploiting an authenticated command injection in the payload builder page.
Insurance version 1.2 suffers from an ignored default credential vulnerability.
Human Resource Management System 2024 version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Hotel Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Hotel Booking System version 1.0 suffers from a remote shell upload vulnerability.
Home Owners Collection Management System version 1.0 suffers from an ignored default credential vulnerability.
Giftora version 1.0 suffers from a cross site scripting vulnerability.
Bhojon Restaurant Management System version 3.0 suffers from an insecure direct object reference vulnerability.