Tag
#windows
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
The APT is pairing a known Microsoft flaw with a malicious document to load malware that nabs credentials from Chrome, Firefox and Edge browsers.
Researchers have spotted the threat group, also known as Fancy Bear and Sofacy, using the Windows MSDT vulnerability to distribute information stealers to users in Ukraine.
Using WebAuthn, physical keys, and biometrics, organizations can adopt more advanced passwordless MFA and true passwordless systems. (Part 2 of 2)
WordPress Download Manager plugin versions 3.2.43 and below suffer from a cross site scripting vulnerability.
Zoo Management System version 1.0 suffers from a cross site scripting vulnerability.