se

Taboola Hack Allows SEA To Redirect Reuters Site Visitors








se

Mozilla's Firefox 70 Is Out: Privacy Reports Reveal Whose Cookies Are Tracking You




se

Secunia Security Advisory 50313

Secunia Security Advisory - A vulnerability has been reported in CuteSoft Cute Editor for ASP.NET, which can be exploited by malicious people to conduct cross-site scripting attacks.




se

Kaseya uploadImage Arbitrary File Upload

This Metasploit module exploits an arbitrary file upload vulnerability found in Kaseya versions below 6.3.0.2. A malicious user can upload an ASP file to an arbitrary directory without previous authentication, leading to arbitrary code execution with IUSR privileges.




se

Numara / BMC Track-It! FileStorageService Arbitrary File Upload

This Metasploit module exploits an arbitrary file upload vulnerability in Numara / BMC Track-It! v8 to v11.X. The application exposes the FileStorageService .NET remoting service on port 9010 (9004 for version 8) which accepts unauthenticated uploads. This can be abused by a malicious user to upload a ASP or ASPX file to the web root leading to arbitrary code execution as NETWORK SERVICE or SYSTEM. This Metasploit module has been tested successfully on versions 11.3.0.355, 10.0.51.135, 10.0.50.107, 10.0.0.143, 9.0.30.248 and 8.0.2.51.




se

Kaseya VSA uploader.aspx Arbitrary File Upload

This Metasploit module exploits an arbitrary file upload vulnerability found in Kaseya VSA versions between 7 and 9.1. A malicious unauthenticated user can upload an ASP file to an arbitrary directory leading to arbitrary code execution with IUSR privileges. This Metasploit module has been tested with Kaseya v7.0.0.17, v8.0.0.10 and v9.0.0.3.




se

ASP Forums 2.1 Database Disclosure

ASP Forums version 2.1 suffers from a database disclosure vulnerability.




se

ASP Gateway 1.0.0 Database Disclosure

ASP Gateway 1.0.0 suffers from a database disclosure vulnerability.













se

Sneaky Malware Disguises Itself As An Adobe Flash Installer




se

Adobe Fixes Over 100 Vulnerabilities In Latest Security Patch Update






se

Adobe Fixes Critical Security Flaws In Flash, ColdFusion, Campaign





se

Adobe Releases Patch For Critical Code Execution Vulnerability




se

Microsoft Warns Of Hacking Group Targeting Vulnerable Web Servers






se

ScanGuard Antivirus Insecure Permissions

Scanguard versions through 2019-11-12 on Windows has insecure permissions for the installation directory, leading to privilege escalation via a trojan horse executable file.









se

IBM Reports Huge Rise In Malicious Links




se

IBM And Verizon Take Security To The Cloud




se

Google Corrects IBM's Security Math




se

McAfee, IBM Gobble Rival Security Intelligence Firms









se

Vietnamese Security Firm - Your Face Is Easy To Fake




se

Vietnamese Dissidents Targeted By Botnet Attacks




se

Vietnamese Government Denies Aurora-Style Hacks