ge Create-Project Manager 1.07 Cross Site Scripting / HTML Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:30:17 GMT Create-Project Manager version 1.07 suffers from cross site scripting and html injection vulnerabilities. Full Article
ge Western Intelligence Hacked Yandex To Spy On Accounts By packetstormsecurity.com Published On :: Fri, 28 Jun 2019 15:12:22 GMT Full Article headline hacker government usa canada britain russia cyberwar new zealand
ge DDoS Kingpin Gets 13 Months, Massive Fine By packetstormsecurity.com Published On :: Sat, 16 Nov 2019 15:34:54 GMT Full Article headline usa canada cybercrime denial of service fraud
ge Gentoo Linux Security Advisory 202003-06 By packetstormsecurity.com Published On :: Fri, 13 Mar 2020 14:58:36 GMT Gentoo Linux Security Advisory 202003-6 - Multiple vulnerabilities have been found in Ruby, the worst of which could lead to the remote execution of arbitrary code. Versions less than 2.4.9:2.4 are affected. Full Article
ge Gentoo Linux Security Advisory 202003-09 By packetstormsecurity.com Published On :: Sat, 14 Mar 2020 17:08:19 GMT Gentoo Linux Security Advisory 202003-9 - A vulnerability in OpenID library for Ruby at worst might allow an attacker to bypass authentication. Versions less than 2.9.2 are affected. Full Article
ge Former Twitter Employees Charged With Spying On Users For Saudis By packetstormsecurity.com Published On :: Thu, 07 Nov 2019 14:51:02 GMT Full Article headline government cybercrime fraud spyware social saudi arabia twitter
ge Authorities Make Arrest Of Alleged Hacker That Hacked Jack Dorsey By packetstormsecurity.com Published On :: Tue, 26 Nov 2019 17:33:34 GMT Full Article headline hacker phone twitter
ge Windows Mobile 6.5 MessageBox Shellcode By packetstormsecurity.com Published On :: Tue, 28 Sep 2010 01:53:25 GMT Windows Mobile version 6.5 TR (WinCE 5.2) MessageBox shellcode for ARM. Full Article
ge MS13-005 HWND_BROADCAST Low to Medium Integrity Privilege Escalation By packetstormsecurity.com Published On :: Mon, 29 Jul 2013 22:14:06 GMT The Windows kernel does not properly isolate broadcast messages from low integrity applications from medium or high integrity applications. This allows commands to be broadcasted to an open medium or high integrity command prompts allowing escalation of privileges. We can spawn a medium integrity command prompt, after spawning a low integrity command prompt, by using the Win+Shift+# combination to specify the position of the command prompt on the taskbar. We can then broadcast our command and hope that the user is away and doesn't corrupt it by interacting with the UI. Broadcast issue affects versions Windows Vista, 7, 8, Server 2008, Server 2008 R2, Server 2012, RT. But Spawning a command prompt with the shortcut key does not work in Vista so you will have to check if the user is already running a command prompt and set SPAWN_PROMPT false. The WEB technique will execute a powershell encoded payload from a Web location. The FILE technique will drop an executable to the file system, set it to medium integrity and execute it. The TYPE technique will attempt to execute a powershell encoded payload directly from the command line but it may take some time to complete. Full Article
ge MS14-060 Microsoft Windows OLE Package Manager Code Execution By packetstormsecurity.com Published On :: Sat, 18 Oct 2014 00:42:31 GMT This Metasploit module exploits a vulnerability found in Windows Object Linking and Embedding (OLE) allowing arbitrary code execution, publicly known as "Sandworm". Platforms such as Windows Vista SP2 all the way to Windows 8, Windows Server 2008 and 2012 are known to be vulnerable. Full Article
ge MS14-064 Microsoft Windows OLE Package Manager Code Execution By packetstormsecurity.com Published On :: Thu, 13 Nov 2014 17:32:46 GMT This Metasploit module exploits a vulnerability found in Windows Object Linking and Embedding (OLE) allowing arbitrary code execution, publicly exploited in the wild as MS14-060 patch bypass. The Microsoft update tried to fix the vulnerability publicly known as "Sandworm". Platforms such as Windows Vista SP2 all the way to Windows 8, Windows Server 2008 and 2012 are known to be vulnerable. However, based on our testing, the most reliable setup is on Windows platforms running Office 2013 and Office 2010 SP2. And please keep in mind that some other setups such as using Office 2010 SP1 might be less stable, and sometimes may end up with a crash due to a failure in the CPackage::CreateTempFileName function. Full Article
ge MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python By packetstormsecurity.com Published On :: Fri, 14 Nov 2014 00:34:29 GMT This Metasploit module exploits a vulnerability found in Windows Object Linking and Embedding (OLE) allowing arbitrary code execution, bypassing the patch MS14-060, for the vulnerability publicly known as "Sandworm", on systems with Python for Windows installed. Windows Vista SP2 all the way to Windows 8, Windows Server 2008 and 2012 are known to be vulnerable. However, based on our testing, the most reliable setup is on Windows platforms running Office 2013 and Office 2010 SP2. Please keep in mind that some other setups such as those using Office 2010 SP1 may be less stable, and may end up with a crash due to a failure in the CPackage::CreateTempFileName function. Full Article
ge GE Employees Lit Up With Sensitive Doc Breach By packetstormsecurity.com Published On :: Thu, 26 Mar 2020 14:39:12 GMT Full Article headline privacy data loss
ge Personal Details For Entire Country Of Georgia Leaked Online By packetstormsecurity.com Published On :: Mon, 30 Mar 2020 15:32:42 GMT Full Article headline government privacy data loss
ge American Gets Targeted By Spy Tool Sold To Foreign Governments By packetstormsecurity.com Published On :: Tue, 04 Jun 2013 13:41:22 GMT Full Article headline government privacy malware usa spyware turkey
ge Turkey Blocks Twitter, YouTube Over Hostage Photos By packetstormsecurity.com Published On :: Mon, 06 Apr 2015 14:25:37 GMT Full Article headline cyberwar turkey twitter censorship
ge These Ten Cities Are Home To The Biggest Botnets By packetstormsecurity.com Published On :: Tue, 04 Oct 2016 14:54:09 GMT Full Article headline malware cybercrime denial of service botnet fraud turkey
ge Solaris 11.4 xscreensaver Privilege Escalation By packetstormsecurity.com Published On :: Wed, 16 Oct 2019 15:03:23 GMT Solaris version 11.4 xscreensaver local privilege escalation exploit. Full Article
ge Solaris xscreensaver Privilege Escalation By packetstormsecurity.com Published On :: Wed, 23 Oct 2019 20:15:30 GMT This Metasploit module exploits a vulnerability in xscreensaver versions since 5.06 on unpatched Solaris 11 systems which allows users to gain root privileges. xscreensaver allows users to create a user-owned file at any location on the filesystem using the -log command line argument introduced in version 5.06. This module uses xscreensaver to create a log file in /usr/lib/secure/, overwrites the log file with a shared object, and executes the shared object using the LD_PRELOAD environment variable. This module has been tested successfully on xscreensaver version 5.15 on Solaris 11.1 (x86) and xscreensaver version 5.15 on Solaris 11.3 (x86). Full Article
ge SunOS 5.10 Generic_147148-26 Local Privilege Escalation By packetstormsecurity.com Published On :: Wed, 15 Jan 2020 23:33:33 GMT SunOS version 5.10 Generic_147148-26 local privilege escalation exploit. A buffer overflow in the CheckMonitor() function in the Common Desktop Environment versions 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in a malicious .Xdefaults file. Full Article
ge Common Desktop Environment 1.6 Local Privilege Escalation By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 22:34:40 GMT A buffer overflow in the _SanityCheck() function in the Common Desktop Environment version distributed with Oracle Solaris 10 1/13 (Update 11) and earlier allows local users to gain root privileges via a long calendar name or calendar owner passed to sdtcm_convert in a malicious calendar file. The open source version of CDE (based on the CDE 2.x codebase) is not affected, because it does not ship the vulnerable program. Versions 1.6 and below are affected. Full Article
ge MaMi Malware Targets Mac OS X DNS Settings By packetstormsecurity.com Published On :: Mon, 15 Jan 2018 15:56:32 GMT Full Article headline malware dns fraud apple
ge DNSpionage Actors Adjust Tactics, Debut New RAT By packetstormsecurity.com Published On :: Thu, 25 Apr 2019 15:52:44 GMT Full Article headline hacker government dns fraud cyberwar
ge Open-Xchange OX App Suite Content Spoofing / Cross Site Scripting By packetstormsecurity.com Published On :: Fri, 16 Aug 2019 21:17:15 GMT Open-Xchange OX App Suite suffers from a content spoofing, cross site scripting, and information disclosure vulnerabilities. Versions affected vary depending on the vulnerability. Full Article
ge Gentoo Linux Security Advisory 202004-06 By packetstormsecurity.com Published On :: Fri, 03 Apr 2020 02:51:49 GMT Gentoo Linux Security Advisory 202004-6 - A regression in GnuTLS breaks the security guarantees of the DTLS protocol. Versions less than 3.6.13 are affected. Full Article
ge User Management System 2.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:23:07 GMT User Management System version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Full Article
ge Complaint Management System 4.2 SQL Injection By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:29:20 GMT Complaint Management System version 4.2 suffers a remote SQL injection vulnerability that allows for authentication bypass. Full Article
ge Geeklog 2.2.1 SQL Injection By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 15:18:37 GMT Geeklog version 2.2.1 suffers from a remote SQL injection vulnerability. Full Article
ge iJoomla AdAgency 6.0.9 SQL Injection By packetstormsecurity.com Published On :: Sat, 02 May 2020 16:22:22 GMT iJoomla AdAgency component version 6.0.9 suffers from a remote SQL injection vulnerability. Full Article
ge Online AgroCulture Farm Management System 1.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:15:37 GMT Online AgroCulture Farm Management System version 1.0 suffers from a remote SQL injection vulnerability. Full Article
ge School File Management System 1.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:16:26 GMT School File Management System version 1.0 suffers from a remote SQL injection vulnerability. Full Article
ge Car Park Management System 1.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:20:46 GMT Car Park Management System version 1.0 suffers a remote SQL injection vulnerability that allows for authentication bypass. Full Article
ge Gadgets Can Be Hacked To Produce Dangerous Sounds By packetstormsecurity.com Published On :: Sun, 11 Aug 2019 18:14:53 GMT Full Article headline flaw cyberwar science conference
ge Team That Made Gene-Edited Babies Sentenced To Prison, Fined By packetstormsecurity.com Published On :: Thu, 02 Jan 2020 16:04:59 GMT Full Article headline china fraud science
ge First Clinical Trial Of Gene Editing To Help Target Cancer By packetstormsecurity.com Published On :: Fri, 07 Feb 2020 13:39:23 GMT Full Article headline science
ge Smart Thermometers Detect Large Fever Outbreak In Florida By packetstormsecurity.com Published On :: Tue, 24 Mar 2020 15:19:33 GMT Full Article headline government usa virus science
ge How Coronavirus Sentiment And Behavior Has Changed By packetstormsecurity.com Published On :: Tue, 31 Mar 2020 14:09:43 GMT Full Article headline government science
ge Apple Tracks Changes In Pandemic Travel Behavior By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:06:55 GMT Full Article headline privacy apple science
ge OpenBSD Patches Auth Bypass, Privilege Escalation Vulns By packetstormsecurity.com Published On :: Thu, 05 Dec 2019 16:54:00 GMT Full Article headline flaw bsd patch
ge British Airways E-Ticketing Flaw Exposes Passenger Flight, Personal Data By packetstormsecurity.com Published On :: Tue, 13 Aug 2019 14:29:35 GMT Full Article headline privacy britain data loss terror
ge Teenagers Arrested Over Hacks To Met Police Website By packetstormsecurity.com Published On :: Fri, 11 Oct 2019 14:57:15 GMT Full Article headline hacker government britain
ge Assange Fails To Delay Extradition Hearing As Date Set For February By packetstormsecurity.com Published On :: Tue, 22 Oct 2019 17:09:58 GMT Full Article headline government usa britain russia data loss spyware military
ge Hacker Who Blackmailed Apple In 2017 Gets No Prison Time By packetstormsecurity.com Published On :: Sat, 21 Dec 2019 06:49:02 GMT Full Article headline hacker britain fraud apple
ge National Lottery Sentry MBA Hacker Gets 9 Months In Jail By packetstormsecurity.com Published On :: Fri, 10 Jan 2020 15:30:48 GMT Full Article headline hacker britain cybercrime fraud
ge Australian MPs Call On UK To Block US Assange Extradition By packetstormsecurity.com Published On :: Wed, 19 Feb 2020 14:57:28 GMT Full Article headline government usa britain australia data loss cyberwar spyware
ge US, UK Blame Russia For Mass Defacement Of Georgian Websites By packetstormsecurity.com Published On :: Thu, 20 Feb 2020 15:10:15 GMT Full Article headline government usa britain russia cyberwar
ge UK To Launch Specialist Cyber Force Able To Target Terror By packetstormsecurity.com Published On :: Fri, 28 Feb 2020 07:05:28 GMT Full Article headline hacker government britain cyberwar terror military
ge UK Home Office Breached GDPR 100 Times Through Botched Management Of EU Settlement Scheme By packetstormsecurity.com Published On :: Mon, 02 Mar 2020 15:21:11 GMT Full Article headline government privacy britain data loss
ge Loyalty Cards Targeted In Tesco Clubcard Attack By packetstormsecurity.com Published On :: Thu, 05 Mar 2020 14:35:27 GMT Full Article headline hacker britain data loss fraud
ge Alleged Computer Hacker Granted Bail By packetstormsecurity.com Published On :: Wed, 23 Sep 2009 04:58:22 GMT Full Article hacker caribbean