• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

reference

  1. 1

    Exploits Microsoft Word (2016) Deceptive File Reference

    When a Microsoft Word ".docx" File contains a hyperlink to another file, it will run the first file it finds in that directory with a valid extension. But will present to the end user an extension-less file in its Security warning dialog box without showing the extension type. If another "empty"...
  2. 1

    Exploits Linux kvm_ioctl_create_device() Reference Flow Failure

    Linux kvm_ioctl_create_device() installs fd before taking reference. View the full article
  3. 1

    Exploits LongBox Limited Access Manager Insecure Direct Object Reference

    LongBox Limited Access Manager suffers from an insecure direct object reference vulnerability. This issue affects Access Manager versions 1.2 through 1.4-RG3. It has been addressed in versions greater than or equal to 1.4-RG4. View the full article
  4. 1

    Exploits VBScript VbsErase Reference Leak

    There is an reference leak in Microsoft VBScript that can be turned into an use-after-free given sufficient time. The vulnerability has been confirmed in Internet Explorer on various Windows versions with the latest patches applied. View the full article
  5. 1

    Exploits Fortify SSC 17.10 / 17.20 / 18.10 User Detail Insecure Direct Object Reference

    Fortify Software Security Center versions 17.10, 17.20, and 18.10 suffer from an insecure direct object reference vulnerability related to extracting local and ldap users. View the full article
  6. 1

    Exploits Fortify SSC 17.10 / 17.20 / 18.10 Insecure Direct Object Reference

    Fortify Software Security Center versions 17.10, 17.20, and 18.10 suffer from an insecure direct object reference vulnerability. View the full article
  7. 1

    Exploits Wisetail Learning Ecosystem 4.11.6 Insecure Direct Object Reference

    Wisetail Learning Ecosystem (LE) versions up to 4.11.6 suffer from multiple insecure direct object reference vulnerabilities that allow an attacker to download files and get access to the non-purchased course quiz test via a modified id parameter. View the full article
  8. 1

    Exploits OSCAR EMR 15.21beta361 XSS / Disclosure / CSRF / Insecure Direct Object Reference

    OSCAR EMR version 15.21beta361 suffers from remote code execution, cross site request forgery, cross site scripting, denial of service, deserialization, remote SQL injection, and path traversal vulnerabilities. View the full article
Back
Top