On Windows, the Kerberos ticket renewal process can be used with CG to get an unencrypted TGT session key for a currently authenticated user leading to information disclosure.
>> ARCHIVE: 2022-09
XML signature verification in .NET 6 as implemented in System.Security.Cryptography.Xml.SignedXml is vulnerable to external entity injection attacks.
Sagemath version 9.0 suffers from overflow and denial of service vulnerabilities.
http://amss.ayutthaya2.go.th/read.html notified by ./Niz4r
http://salary.ayutthaya2.go.th/read.html notified by ./Niz4r
http://sawat.ayutthaya2.go.th/read.html notified by ./Niz4r
http://smss.ayutthaya2.go.th/read.html notified by ./Niz4r
This Metasploit module exploits an unauthenticated command injection vulnerability in Apache Spark. Successful exploitation results in remote code execution under the context of the Spark application user. The command injection…
Trojan.Win32.Autoit.fhj malware suffers from an insecure permissions vulnerability.
FTPManager version 8.2 suffers from local file inclusion and directory traversal vulnerabilities.