Release date:
Updated on:
Affected Systems:
ACTi ACD-2100 Video Encoder
ACTi ACM-1432 Bullet Camera
Description:
--------------------------------------------------------------------------------
ACTi mainly produces, develops, and sells products and services such as IP monitoring, end-to-end solution development and integration, and business model.
The Web configuration program of multiple AcTi products has the Shell command injection
Release date:Updated on:
Affected Systems:Opera Software Opera Web Browser 11.xDescription:--------------------------------------------------------------------------------Bugtraq id: 55301
Opera provides free Web browsers for computers, mobile phones, and devices.
A remote code execution vulnerability exists in versions earlier than Opera 12.02 and 11.67. Atta
Release date:Updated on:
Affected Systems:Drupal RESTful Web Services Module 7.xDescription:--------------------------------------------------------------------------------Drupal is an open source content management platform.
Drupal's RESTful Web Services Module has a security vulnerability and does not correctly verify certain HTTP requests. Attackers can expl
Release date: 2013-03-21Updated on: 2013-04-12
Affected Systems:AirDroidDescription:--------------------------------------------------------------------------------CVE (CAN) ID: CVE-2013-0134AirDroid is a remote mobile phone management software.The AirDroid Web interface has the cross-site scripting vulnerability. Remote attackers can exploit this vulnerability
To do web development, we often do code walk-through, many times, we will check some core features, or often appear the logic of loopholes. Along with the technical team's growth, the crew technology matures. Common fool-type SQL injection vulnerabilities, and XSS vulnerabilities. will be less, but we will also find that some emerging hidden vulnerabilities occasionally emerge. These vulnerabilities are more from developers, to a function, common modu
Happy web SQL Injection Vulnerability
Happy web SQL Injection Vulnerability
Many websites of Happy color network adopt thinkphp framework for development. Because patches are not updated in time, there is a general injection. See 2cto: SQL Injection. injection 1 in the ThinkPHP framework architecture:Http://lebi.17500.
D-Link DSL-2740R Web Interface Remote Poisoning Vulnerability
Release date:Updated on:
Affected Systems:D-Link DSL-2740RDescription:Bugtraq id: 72339
The DSL-2740R is a wireless N300 ADSL2 + wireless router.
D-Link DSL-2740R in the implementation of DNS settings Modification Vulnerability, remote attackers can exploit this
Release date:Updated on:
Affected Systems:EFS Software Easy File Sharing Web Server 6.8Description:--------------------------------------------------------------------------------Bugtraq id: 67406CVE (CAN) ID: CVE-2014-3791Easy File Sharing Web Server is a File Sharing software. Users can upload and download files in a browser.Some user input is not correctly verified when Easy File Sharing
Remote executable command vulnerability in Sun Java Web ServerVulnerability release Time: 2000-7-13 17:41:00Leakage description:Under the default installation settings of Sun Java Web Server on Solaris and Windows NT. Attackers can remotely execute arbitrary commands by exploiting vulnerabilities in the template program of the bulletin board version.The
ContentKeeper Web remote command execution Security Vulnerability
Release date:Updated on:
Affected Systems:ContentKeeper Technologies ContentKeeper Description:--------------------------------------------------------------------------------ContentKeeper is an advanced Internet content filter that allows organizations to monitor and manage access to Internet resources.
ContentKeeper has the remote comman
Release date:Updated on:
Affected Systems:Samba 3.0.x-4.0.1Description:--------------------------------------------------------------------------------CVE (CAN) ID: CVE-2013-0214Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.Samba 3.x, 4. x's Samba Web Administration Tool (SWAT) has a Cross-Site Request Forgery Vulnerabilit
Release date:Updated on:
Affected Systems:Cisco SA540 2.1.18Cisco SA520W 2.1.18Unaffected system:Cisco SA540 2.1.19Cisco SA520W 2.1.19Description:--------------------------------------------------------------------------------Bugtraq id: 48810Cve id: CVE-2011-2547
Cisco SA 500 series security devices are integrated security solutions for small businesses with less than 100 employees.
A remote command injection vulnerability exists in the implementatio
Release date: 2012-08-02Updated on:
Affected Systems:Opera Software Opera Web Browser 12.xOpera Software Opera Web Browser 11.xDescription:--------------------------------------------------------------------------------Bugtraq id: 54779
Opera is a browser from Norway.
The implementation of Opera Web Browser 12.01 and earlier versions has the HTML injection
Identify Web pages with crawlers
Multithreading
Maximum number of threads that can be controlled
Page to control crawler crawling
You can omit the specified file name extension
Can set the GET, Post mode
Support SSL
Support Agent
List of sites that support Google search
List of sites that support Bing search
Support for extensions (dynamic, static, stress test)
Multi-lingual support
Support GUI interface
Directory check, simi
Today, because of the project background, it is necessary to detect the Web interface for some security risks.But has never mastered the knowledge of systematic permeability, had to do some exploration according to the personal understanding of the network protocol and the Web, finally found a session fixation attacks loophole.Scene review:Using the capture tool to monitor the login log out interface of the
How to better achieve the prevention of hacker attacks, I mention personal views! First, the free program does not really have a fee, since you can share the original code, then the attacker can analyze the code. If you pay attention to precautions in detail, your site's security will be greatly improved. Even if there are vulnerabilities such as SQL injection, attackers will not be able to take your site immediately.
Due to the ease of use of ASP, more and more
Introduction
EFS Web server is a software that can manage server files over a Web side, and sending a GET request too long can trigger a buffer overflow vulnerabilityAnalysis Source: https://www.exploit-db.com/exploits/39008/ Experimental Environment
WinXP SP3 Chinese versionEFS Web Server7.2Immunity DebuggerWinDbgIdaMona Vu
Release date:Updated on:
Affected Systems:Symantec Web Gateway 5.0.3Symantec Web Gateway 5.0.1Description:--------------------------------------------------------------------------------Bugtraq id: 54429Cve id: CVE-2012-2957
Symantec Web Gateway is a Symantec Enterprise Web threat protection solution.
Symantec
From the system installation to the user security settings, system permissions settings to explain the Web server Trojan Horse and vulnerability attacks, the right configuration, I hope this article can make your server more secure.
First, the system installation
1, according to the WINDOWS2003 installation CD-ROM prompts installation, by default, 2003 did not install IIS6.0 installed in the system. 2, t
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.