j Unprecedented DNS Hijacking Attacks Linked To Iran By packetstormsecurity.com Published On :: Sat, 12 Jan 2019 16:36:04 GMT Full Article headline dns iran
j GoDaddy Weakness Let Domains Be Hijacked By packetstormsecurity.com Published On :: Wed, 23 Jan 2019 15:19:15 GMT Full Article headline privacy dns cybercrime fraud
j A Deep Dive On The Recent Widespread DNS Hijacking Attacks By packetstormsecurity.com Published On :: Tue, 19 Feb 2019 15:23:06 GMT Full Article headline hacker privacy dns cyberwar phish
j State-Sponsored DNS Hijacking Infiltrates 40 Firms Globally By packetstormsecurity.com Published On :: Thu, 18 Apr 2019 13:07:29 GMT Full Article headline hacker government dns cyberwar
j DNSpionage Actors Adjust Tactics, Debut New RAT By packetstormsecurity.com Published On :: Thu, 25 Apr 2019 15:52:44 GMT Full Article headline hacker government dns fraud cyberwar
j Vast Majority Of Newly Registered Domains Are Malicious By packetstormsecurity.com Published On :: Thu, 22 Aug 2019 15:44:39 GMT Full Article headline dns cybercrime fraud
j Johnny You Are Fired By packetstormsecurity.com Published On :: Wed, 01 May 2019 14:44:44 GMT This archive contains proof of concepts and a whitepaper that describes multiple email client implementations where popular clients for email are vulnerable to signature spoofing attacks. Full Article
j Git Credential Helper Protocol Newline Injection By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:45:49 GMT A git clone action can leak cached / stored credentials for github.com to example.com due to insecure handling of newlines in the credential helper protocol. Full Article
j Macs Framework 1.14f Cross Site Scripting / SQL Injection By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:33:28 GMT Macs Framework version 1.14f suffers from cross site scripting and remote SQL injection vulnerabilities. Full Article
j Centreon 19.10.5 SQL Injection By packetstormsecurity.com Published On :: Mon, 20 Apr 2020 15:21:10 GMT Centreon version 19.10.5 suffers from a remote SQL injection vulnerability. Full Article
j PMB 5.6 SQL Injection By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 14:14:25 GMT PMB version 5.6 suffers from a remote SQL injection vulnerability. Full Article
j User Management System 2.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:23:07 GMT User Management System version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. Full Article
j Complaint Management System 4.2 SQL Injection By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:29:20 GMT Complaint Management System version 4.2 suffers a remote SQL injection vulnerability that allows for authentication bypass. Full Article
j Online Shopping System Advanced 1.0 SQL Injection By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 14:56:10 GMT Online Shopping System Advanced version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j Online Course Registration 2.0 SQL Injection By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 15:05:54 GMT Online Course Registration 2.0 suffers from authentication bypass and remote SQL injection vulnerabilities. Full Article
j Geeklog 2.2.1 SQL Injection By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 15:18:37 GMT Geeklog version 2.2.1 suffers from a remote SQL injection vulnerability. Full Article
j Project Open CMS 5.0.3 Cross Site Scripting / SQL Injection By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 14:48:04 GMT Project Open CMS version 5.0.3 suffers from cross site scripting and remote SQL injection vulnerabilities. Full Article
j School ERP Pro 1.0 SQL Injection By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:31:19 GMT School ERP Pro version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j Open-AudIT 3.2.2 Command Injection / SQL Injection By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:39:24 GMT Open-AudIT version 3.2.2 suffers from OS command injection, arbitrary file upload, and remote SQL injection vulnerabilities. Full Article
j hits script 1.0 SQL Injection By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:58:05 GMT hits script version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j iJoomla AdAgency 6.0.9 SQL Injection By packetstormsecurity.com Published On :: Sat, 02 May 2020 16:22:22 GMT iJoomla AdAgency component version 6.0.9 suffers from a remote SQL injection vulnerability. Full Article
j Fishing Reservation System SQL Injection By packetstormsecurity.com Published On :: Mon, 04 May 2020 09:02:22 GMT Fishing Reservation System suffers from multiple remote SQL injection vulnerabilities. Full Article
j addressbook 9.0.0.1 SQL Injection By packetstormsecurity.com Published On :: Mon, 04 May 2020 17:19:23 GMT addressbook version 9.0.0.1 suffers from a remote SQL injection vulnerability. Full Article
j Online Scheduling System 1.0 SQL Injection By packetstormsecurity.com Published On :: Tue, 05 May 2020 20:46:22 GMT Online Scheduling System version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j Pisay Online E-Learning System 1.0 SQL Injection / Code Execution By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:40:34 GMT Pisay Online E-Learning System version 1.0 suffers from remote SQL Injection and code execution vulnerabilities. Full Article
j YesWiki cercopitheque 2020.04.18.1 SQL Injection By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:44:02 GMT YesWiki cercopitheque version 2020.04.18.1 suffers from a remote SQL injection vulnerability. Full Article
j Online Clothing Store 1.0 SQL Injection By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:52:19 GMT Online Clothing Store version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j Online AgroCulture Farm Management System 1.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:15:37 GMT Online AgroCulture Farm Management System version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j School File Management System 1.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:16:26 GMT School File Management System version 1.0 suffers from a remote SQL injection vulnerability. Full Article
j Car Park Management System 1.0 SQL Injection By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:20:46 GMT Car Park Management System version 1.0 suffers a remote SQL injection vulnerability that allows for authentication bypass. Full Article
j WordPress ChopSlider 3 SQL Injection By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:47:15 GMT WordPress ChopSlider plugin version 3 suffers from a remote SQL injection vulnerability. Full Article
j Creative Zone SQL Injection By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:53:09 GMT Creative Zone suffers from a remote SQL injection vulnerability. Full Article
j The US Army Just Contracted With A UFO Group To Study Alien Alloys By packetstormsecurity.com Published On :: Sat, 19 Oct 2019 15:37:02 GMT Full Article headline government usa space science military
j FreeBSD Project Reveals Servers Were Compromised By packetstormsecurity.com Published On :: Mon, 19 Nov 2012 16:04:03 GMT Full Article headline hacker data loss bsd backdoor
j National Lottery Sentry MBA Hacker Gets 9 Months In Jail By packetstormsecurity.com Published On :: Fri, 10 Jan 2020 15:30:48 GMT Full Article headline hacker britain cybercrime fraud
j Look Who's Joined The Anti-Encryption Posse: Germany, Come On Down By packetstormsecurity.com Published On :: Fri, 16 Jun 2017 14:11:25 GMT Full Article headline government privacy usa britain germany backdoor cryptography
j German Hacker Offers Rare Look Inside Secretive World Of Julian Assange, WikiLeaks By packetstormsecurity.com Published On :: Thu, 18 Jan 2018 04:24:47 GMT Full Article headline hacker government britain data loss germany
j IPhone TreasonSMS HTML Injection / File Inclusion By packetstormsecurity.com Published On :: Mon, 23 Apr 2012 18:55:33 GMT IPhone TreasonSMS suffers from html injection and file inclusion vulnerabilities. Full Article
j Air Disk Wireless 1.9 LFI / Command Injection By packetstormsecurity.com Published On :: Fri, 08 Feb 2013 03:40:19 GMT Air Disk Wireless version 1.9 for iPad and iPhone suffers from local file inclusion and command injection vulnerabilities. Full Article
j Transferable Remote 1.1 XSS / LFI / Command Injection By packetstormsecurity.com Published On :: Wed, 13 Feb 2013 03:00:01 GMT Transferable Remote version 1.1 for iPad and iPhone suffers from cross site scripting, remote command injection, and local file inclusion vulnerabilities. Full Article
j Shanghai Jiao Tong University Exposed 8.4TB Of Email Data By packetstormsecurity.com Published On :: Mon, 10 Jun 2019 19:57:39 GMT Full Article headline privacy email china data loss
j SQLMAP - Automatic SQL Injection Tool 1.4.5 By packetstormsecurity.com Published On :: Mon, 04 May 2020 17:30:13 GMT sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more. Full Article
j TP-LINK Cloud Cameras NCXXX Bonjour Command Injection By packetstormsecurity.com Published On :: Fri, 01 May 2020 22:22:22 GMT TP-LINK Cloud Cameras including products NC200, NC210, NC220, NC230, NC250, NC260, and NC450 suffer from a command injection vulnerability. The issue is located in the swSystemSetProductAliasCheck method of the ipcamera binary (Called when setting a new alias for the device via /setsysname.fcgi), where despite a check on the name length, no other checks are in place in order to prevent shell metacharacters from being introduced. The system name would then be used in swBonjourStartHTTP as part of a shell command where arbitrary commands could be injected and executed as root. Full Article
j SpeakUp Linux Backdoor Sets Up For Major Attack By packetstormsecurity.com Published On :: Mon, 04 Feb 2019 15:20:15 GMT Full Article headline hacker linux botnet backdoor
j Linux Bug Opens Most VPNs To Hijacking By packetstormsecurity.com Published On :: Mon, 09 Dec 2019 15:12:01 GMT Full Article headline hacker privacy linux flaw cryptography
j Lazarus Pivots To Linux Attacks Through Dacls Trojan By packetstormsecurity.com Published On :: Tue, 17 Dec 2019 15:36:58 GMT Full Article headline malware linux trojan backdoor
j SkyJack Drone Hijacker By packetstormsecurity.com Published On :: Wed, 04 Dec 2013 03:19:46 GMT Skyjack takes over Parrot drones, deauthenticating their true owner and taking over control, turning them into zombie drones under your own control. Full Article
j Teltonika RUT9XX Unauthenticated OS Command Injection By packetstormsecurity.com Published On :: Fri, 12 Oct 2018 16:16:15 GMT Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges. Full Article
j Imperva SecureSphere 13.x PWS Command Injection By packetstormsecurity.com Published On :: Wed, 06 Mar 2019 18:19:49 GMT This Metasploit module exploits a command injection vulnerability in Imperva SecureSphere version 13.x. The vulnerability exists in the PWS service, where Python CGIs did not properly sanitize user supplied command parameters and directly passes them to corresponding CLI utility, leading to command injection. Agent registration credential is required to exploit SecureSphere in gateway mode. This module was successfully tested on Imperva SecureSphere 13.0/13.1/13.2 in pre-ftl mode and unsealed gateway mode. Full Article
j Sierra Wireless AirLink ES450 ACEManager iplogging.cgi Command Injection By packetstormsecurity.com Published On :: Fri, 26 Apr 2019 19:32:22 GMT An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this vulnerability. Full Article