on Online Book Store 1.0 Arbitrary File Upload By packetstormsecurity.com Published On :: Thu, 16 Jan 2020 02:22:22 GMT Online Book Store version 1.0 suffers from an arbitrary file upload vulnerability. Full Article
on WordPress Event-Registration 5.43 Arbitrary File Upload By packetstormsecurity.com Published On :: Mon, 30 Mar 2020 11:11:11 GMT WordPress Event-Registration plugin version 5.43 suffers from an arbitrary file upload vulnerability. Full Article
on Playable 9.18 Script Insertion / Arbitrary File Upload By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 15:28:08 GMT Playable version 9.18 for iOS suffers from script insertion and arbitrary file upload vulnerabilities. Full Article
on Gigamon GigaVUE 5.5.01.11 Directory Traversal / File Upload By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:53:01 GMT Gigamon GigaVUE version 5.5.01.11 suffers from directory traversal and file upload with command execution vulnerabilities. Gigamon has chosen to sunset this product and not offer a patch. Full Article
on Online Clothing Store 1.0 Arbitrary File Upload By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:26:30 GMT Online Clothing Store version 1.0 suffers from an arbitrary file upload vulnerability. Full Article
on Samsung Adds Biometrics To Latest Galaxy Smartphone By packetstormsecurity.com Published On :: Tue, 25 Feb 2014 01:17:13 GMT Full Article headline phone password science samsung
on Samsung Find My Phone Severely Flawed By packetstormsecurity.com Published On :: Wed, 29 Oct 2014 13:14:32 GMT Full Article headline phone flaw samsung
on Samsung Warns Their TVs Can Spy On You By packetstormsecurity.com Published On :: Mon, 09 Feb 2015 16:20:21 GMT Full Article headline privacy data loss spyware samsung
on FAA Considers A Ban On Samsung's Exploding Smartphones By packetstormsecurity.com Published On :: Thu, 08 Sep 2016 13:26:03 GMT Full Article headline phone flaw samsung
on Samsung Bug Allows Any Fingerprint To Unlock Phones By packetstormsecurity.com Published On :: Fri, 18 Oct 2019 14:59:52 GMT Full Article headline phone flaw password samsung
on Trump Admin Wants To Extend NSA Phone Surveillance Program By packetstormsecurity.com Published On :: Fri, 16 Aug 2019 16:22:15 GMT Full Article headline government privacy usa phone spyware nsa
on NSA Asks Congress To Permanently Reauthorize Spying Program By packetstormsecurity.com Published On :: Sat, 17 Aug 2019 17:56:14 GMT Full Article headline government privacy usa phone spyware nsa
on Without Encryption We Will Lose All Privacy. This Is Our New Battleground. By packetstormsecurity.com Published On :: Tue, 15 Oct 2019 13:49:15 GMT Full Article headline government privacy usa spyware nsa cryptography
on Kaspersky Identifies APT Mentioned In 2017 Shadow Brokers Leak By packetstormsecurity.com Published On :: Tue, 05 Nov 2019 15:11:59 GMT Full Article headline hacker government malware usa russia cyberwar nsa
on Bills Seeks To Reform NSA Surveillance, Aiming At Section 215, FISA Process By packetstormsecurity.com Published On :: Mon, 27 Jan 2020 22:45:13 GMT Full Article headline government privacy usa phone spyware nsa
on After 4 Years, $100 Million, NSA Gets Only One Lead Phone Snooping By packetstormsecurity.com Published On :: Fri, 28 Feb 2020 07:05:33 GMT Full Article headline privacy phone spyware terror nsa
on Qik Chat 3.0 Command Injection By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:45:56 GMT Qik Chat version 3.0 for iOS suffers from a command injection vulnerability. Full Article
on Service Tracing Privilege Escalation By packetstormsecurity.com Published On :: Fri, 08 May 2020 20:03:43 GMT This Metasploit module leverages a trusted file overwrite with a dll hijacking vulnerability to gain SYSTEM-level access on vulnerable Windows 10 x64 targets. Full Article
on Microsoft Windows NtUserMNDragOver Local Privilege Escalation By packetstormsecurity.com Published On :: Fri, 08 May 2020 20:05:13 GMT This Metasploit module exploits a NULL pointer dereference vulnerability in MNGetpItemFromIndex(), which is reachable via a NtUserMNDragOver() system call. The NULL pointer dereference occurs because the xxxMNFindWindowFromPoint() function does not effectively check the validity of the tagPOPUPMENU objects it processes before passing them on to MNGetpItemFromIndex(), where the NULL pointer dereference will occur. This module has been tested against Windows 7 x86 SP0 and SP1. Offsets within the solution may need to be adjusted to work with other versions of Windows, such as Windows Server 2008. Full Article
on Chinese Firms Leak More Than A Half Billion Resumes By packetstormsecurity.com Published On :: Fri, 05 Apr 2019 15:15:02 GMT Full Article headline privacy china data loss identity theft
on Equifax Data Breach Recovery Costs Pass $1 Billion By packetstormsecurity.com Published On :: Tue, 14 May 2019 00:41:51 GMT Full Article headline hacker privacy cybercrime data loss fraud identity theft
on 4 US Agencies Don't Properly Verify Your Data Due To The Equifax Breach By packetstormsecurity.com Published On :: Fri, 14 Jun 2019 16:08:03 GMT Full Article headline government privacy usa data loss fraud identity theft
on Data Breach Cost Rises To $4 Million Per Incident By packetstormsecurity.com Published On :: Thu, 25 Jul 2019 16:56:59 GMT Full Article headline hacker privacy cybercrime data loss fraud identity theft
on Capital One Shares Drop On Questions Over Hack By packetstormsecurity.com Published On :: Tue, 30 Jul 2019 19:05:15 GMT Full Article headline hacker privacy bank cybercrime data loss fraud identity theft
on Equifax And Beyond: A List Of Major Breaches By packetstormsecurity.com Published On :: Mon, 05 Aug 2019 14:42:20 GMT Full Article headline hacker privacy cybercrime data loss fraud identity theft
on Astronaut Commits Identity Theft From Space By packetstormsecurity.com Published On :: Mon, 26 Aug 2019 13:54:00 GMT Full Article headline bank fraud password identity theft
on Option Way Exposed Personal Info On Customers By packetstormsecurity.com Published On :: Wed, 04 Sep 2019 13:52:48 GMT Full Article headline privacy data loss identity theft
on Now You Have To Jump Through Extra Hoops To Get Money From The Equifax Hack By packetstormsecurity.com Published On :: Mon, 09 Sep 2019 23:41:30 GMT Full Article headline government privacy cybercrime data loss fraud identity theft
on 200K Sign Petition Against Equifax Data Breach Settlement By packetstormsecurity.com Published On :: Mon, 23 Sep 2019 16:52:50 GMT Full Article headline privacy data loss identity theft
on Kenya Passes Data Protection Law Crucial For Tech Investments By packetstormsecurity.com Published On :: Fri, 08 Nov 2019 15:17:13 GMT Full Article headline government data loss africa identity theft
on Understanding The Ripple Effect: Large Enterprise Data Breaches Threaten Everyone By packetstormsecurity.com Published On :: Sat, 09 Nov 2019 13:44:54 GMT Full Article headline hacker privacy data loss password identity theft
on Wawa POS System Compromised For 10 Months By packetstormsecurity.com Published On :: Sat, 21 Dec 2019 06:48:53 GMT Full Article headline hacker malware bank cybercrime fraud identity theft
on Equifax Settles Class-Action Breach Lawsuit For $380.5 Million By packetstormsecurity.com Published On :: Thu, 16 Jan 2020 16:22:22 GMT Full Article headline hacker privacy bank data loss fraud identity theft
on Facebook Agrees To Pay $550 Million To End Facial Recognition Tech Lawsuit By packetstormsecurity.com Published On :: Thu, 30 Jan 2020 15:06:03 GMT Full Article headline government privacy usa data loss identity theft facebook
on New Class Of SQLite Exploits Open Door To iPhone Hack By packetstormsecurity.com Published On :: Sun, 11 Aug 2019 18:14:40 GMT Full Article headline phone database flaw apple conference
on Wyden: Mitch McConnell Wants Foreign Hackers To Help Republicans By packetstormsecurity.com Published On :: Sun, 11 Aug 2019 18:14:49 GMT Full Article headline government usa russia fraud cyberwar conference
on Things Learned From Monitoring Traffic At Defcon By packetstormsecurity.com Published On :: Mon, 12 Aug 2019 16:45:24 GMT Full Article headline privacy wireless conference
on We Asked Def Con Attendees Why People Are Still Getting Hacked By packetstormsecurity.com Published On :: Fri, 16 Aug 2019 16:22:40 GMT Full Article headline hacker conference
on DEF CON China Cancelled Due To Coronavirus By packetstormsecurity.com Published On :: Wed, 29 Jan 2020 15:36:00 GMT Full Article headline virus china conference
on Black Hat Asia 2020 Postponed Due To Coronavirus Concerns By packetstormsecurity.com Published On :: Fri, 14 Feb 2020 14:43:21 GMT Full Article headline china conference
on IBM Pulls Out Of RSA Over Coronavirus Fears By packetstormsecurity.com Published On :: Tue, 18 Feb 2020 15:00:54 GMT Full Article headline ibm conference rsa
on Vendors Ditching RSA Over Coronavirus Fears By packetstormsecurity.com Published On :: Fri, 21 Feb 2020 15:26:53 GMT Full Article headline usa virus china conference rsa
on COVID-19 Visited The RSA Conference This Year By packetstormsecurity.com Published On :: Wed, 11 Mar 2020 13:51:23 GMT Full Article headline virus conference rsa
on PHP-Fusion CMS 9.03 Cross Site Scripting By packetstormsecurity.com Published On :: Wed, 26 Feb 2020 19:33:33 GMT PHP-Fusion CMS versions 9 through 9.03 suffer from multiple cross site scripting vulnerabilities. Full Article
on PHP-FPM 7.x Remote Code Execution By packetstormsecurity.com Published On :: Thu, 05 Mar 2020 21:03:50 GMT This Metasploit module exploits an underflow vulnerability in PHP-FPM versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 of PHP-FPM on Nginx. Only servers with certain Nginx + PHP-FPM configurations are exploitable. This is a port of the original neex's exploit code (see refs). First, it detects the correct parameters (Query String Length and custom header length) needed to trigger code execution. This step determines if the target is actually vulnerable (Check method). Then, the exploit sets a series of PHP INI directives to create a file locally on the target, which enables code execution through a query string parameter. This is used to execute normal payload stagers. Finally, this module does some cleanup by killing local PHP-FPM workers (those are spawned automatically once killed) and removing the created local file. Full Article
on rConfig 3.93 Authenticated Remote Code Execution By packetstormsecurity.com Published On :: Wed, 11 Mar 2020 18:22:22 GMT rConfig version 3.93 suffers from an authenticated ajaxAddTemplate.php remote code execution vulnerability. Full Article
on Horde Groupware Webmail Edition 5.2.22 PHP File Inclusion By packetstormsecurity.com Published On :: Thu, 12 Mar 2020 20:10:33 GMT Horde Groupware Webmail Edition version 5.2.22 suffers from a PHP file inclusion vulnerability. Full Article
on PHPKB Multi-Language 9 image-upload.php Code Execution By packetstormsecurity.com Published On :: Mon, 16 Mar 2020 13:57:49 GMT PHPKB Multi-Language 9 suffers from an image-upload.php remote authenticated code execution vulnerability. Full Article
on rConfig 3.9.4 Remote Command Injection By packetstormsecurity.com Published On :: Mon, 23 Mar 2020 16:08:06 GMT rConfig version 3.9.4 suffers from a search.crud.php remote command injection vulnerability. Full Article
on Horde 5.2.22 CSV Import Code Execution By packetstormsecurity.com Published On :: Mon, 23 Mar 2020 16:17:25 GMT The Horde_Data module version 2.1.4 (and before) present in Horde Groupware version 5.2.22 allows authenticated users to inject arbitrary PHP code thus achieving remote code execution the server hosting the web application. Full Article