Смотрите также связанные темы 22.01.2018 CVE-2013-0209 lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.
18.08.2018 CVE-2008-3703 The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create"snapshots schedules"registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.
11.08.2018 IntelliTamper 2.07 HTTP Header Remote Code Execution Exploit Цель: IntelliTamper 2.07 Воздействие: Выполнение произвольного кода
03.09.2018 Moodle <= 1.8.4 Remote Code Execution Exploit Цель: Moodle 1.8.4 и более ранние версии Воздействие: Выполнение произвольных команд
15.10.2018 PhpWebGallery <= 1.7.2 Session Hijacking / Code Execution Exploit Цель: PhpWebGallery 1.7.2 и более ранние версии Воздействие: Выполнение произвольных команд
23.10.2018 CVE-2008-4728 Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.
23.10.2018 CVE-2008-4729 Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.
06.11.2018 Simple Machines Forum <= 1.1.6 (LFI) Code Execution Exploit Цель: Simple Machines Forum (SMF) 1.1.6 и более ранние версии Воздействие: Выполнение произвольных команд
28.02.2018 Hex Workshop v6 (.HEX File) Local Code Execution Exploit Цель: Hex Workshop v6 Воздействие: Выполнение произвольного кода
11.03.2018 Imera ImeraIEPlugin ActiveX Control Remote Code Execution Exploit Цель: Imera ImeraIEPlugin Воздействие: Выполнение произвольного кода
|