JBoss Application Server Console Cross-Site Scripting Vulnerability

Release date: 2011-12-02Updated on: 2011-12-05 Affected Systems:JBoss Group JBoss Application Server 7.xDescription:--------------------------------------------------------------------------------Bugtraq id: 50885Cve id: CVE-2011-3606 Jboss is a

Apache Struts remote command execution and Arbitrary File Overwrite Vulnerability

Release date:Updated on: Affected Systems:Apache Group Struts 2.xUnaffected system:Apache Group Struts 2.3.1.1Description:--------------------------------------------------------------------------------Bugtraq id: 51257 Apache Struts is an

Barracuda ssl vpn over 680 Cross-Site Scripting Vulnerabilities

Release date:Updated on: 2012-09-05 Affected Systems:Barracuda Networks SSL VPNs 680Description:--------------------------------------------------------------------------------Bugtraq id: 54593Cve id: CVE-2012-4739 Barracuda ssl vpn is a solution

Perl CGI. pm 'set-cookies' and 'p3p' header HTTP Injection Vulnerabilities

Release date:Updated on: Affected Systems:Perl CGI. pm 3.63Description:--------------------------------------------------------------------------------Bugtraq id: 56562Cve id: CVE-2012-5526 Perl CGI. pm is a commonly used Perl module for compiling

Kaspersky Internet Security Remote Denial of Service Vulnerability

Release date:Updated on: Affected Systems:Kaspersky Labs Internet Security 13.xDescription:--------------------------------------------------------------------------------Bugtraq id: 58284 Kaspersky Internet Security is the Kaspersky Internet

D-Link DIR-300/DIR-615 "send_mail" Cross-Site Scripting Vulnerability

Release date:Updated on: Affected Systems:D-Link DIR-615D-Link DIR-300Description:--------------------------------------------------------------------------------DIR-300 and DIR-615 are wireless router products. The validity of parameters passed by

EBay was attacked and urged 0.145 billion million users to change their passwords

According to Reuters, May 23, eBay said on Wednesday that the cyber attacks it launched three months ago have threatened customer data security. The company urged 0.145 billion million users to change their passwords. From the end of February this

Citrix VDI-In-A-Box Authentication Bypass Vulnerability (CVE-2014-3780)

Release date:Updated on: Affected Systems:Citrix VDI-In-A-Box Citrix VDI-In-A-Box Description:--------------------------------------------------------------------------------Bugtraq id: 67687CVE (CAN) ID: CVE-2014-3780 Citrix VDI-In-A-Box is an

Zimbra mail management system 0 day caused by LFI

Zimbra is a company that uses many email systems and may involve many internal secrets, so it is extremely important. This is the day: exploit-db.com that was issued on the http://www.exploit-db.com/exploits/30085/ a few days ago. The local File

How can I detect a virus that has infected my device during iPhone jailbreak?

"The current jailbreak community believes that deleting the Unfold. dylib library and modifying the Apple ID password can avoid the impact of this malicious application," said SektionEins. However, it is not clear how the dynamic library ends on the

Security and design considerations for deploying a VPN

Most enterprises need to protect internet communication. For many enterprises, the simplest way to protect communication is to use virtual private network (VPN) to create an encrypted channel between systems to communicate. The most common use cases

The security management platform is not equal to SOC!

I had a training session last week and talked about the SOC and security management platform. I once again stressed that the security management platform is not equal to the SOC! I have already said this, and it is necessary to give it a try again.

Evaluate database security with database vulnerability scan 6 penetration attacks

In the previous article, we tested the authorization scanning, weak password scanning, and unauthorized scanning of the database vulnerability scanning system. Today we tested the "penetration attack" under the Oracle database ", this module is

Simple Analysis of a nasty rogue promotion software virus

Today, we want to analyze a virtual disk tool software. This virus sample seems to be a normal application after running, but when we exit this program, a series of unexpected things will happen in the future. In the previous rising security monthly,

Remote backup from Linux to Windows using rsync (1)

Rsync is a data image backup tool in Linux. It can be seen from the software name-remote sync. Rsync supports most Unix-like systems, including Linux, Solaris, and BSD. The latest version of rsync can be found at http://rsync.samba.org/rsync. Its

Software encryption using USB flash drives

General USB flash drives do not provide encryption functions. Although the shape of USB flash drives is similar to that of dongles, they are completely different internally. USB flash drives are just a memory chip and a simple ancillary circuit,

Session in PHP and some security measures

One thing we must admit is that most web applications are inseparable from the use of sessions. This article will analyze how to establish a secure session management mechanism based on php and http protocol. First, let's briefly understand some

A good helper for network administrators-Sniffer

Sniffer is a technology that uses computer network interfaces to intercept data packets destined for other computers. This technology is widely used in network maintenance and management. It works like a passive sonar, silently receiving various

Seven factors that make your website no longer secure

Bkjia.com exclusive translation] the traditional opinion is that when surfing the Internet, as long as you do not browse porn, stock investment and gaming websites are secure, however, according to a recent study by Sophos, an IT security and

In-depth analysis of Web 2.0 application security: enterprise-level Web Application Security Solutions

What will happen in cross-site scripting attacks? Cross-site scripting (XSS) is one of the most common application layer attacks that hackers use to intrude into Web applications. XSS is an attack on the customer's privacy of special Web sites. When

Total Pages: 1330 1 .... 78 79 80 81 82 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.