Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports

The recent attack against Microsoft's email infrastructure by a Chinese nation-state actor referred to as Storm-0558 is said to have a broader scope than previously thought. According to cloud security company Wiz, the inactive Microsoft account (MSA) consumer signing key used to forge Azure Active Directory (Azure AD or AAD) tokens to gain illicit access to Outlook Web Access (OWA) and

The Hacker News
#web#windows#microsoft#auth#The Hacker News
WordPress Page Builder KingComposer 2.9.5 Open Redirection

WordPress Page Builder KingComposer plugin version 2.9.5 suffers from an open redirection vulnerability.

CMS-Bank Mellat Payment Manager 1.0.0 Cross Site Scripting

CMS-Bank Mellat Payment Manager version 1.0.0 suffers from a cross site scripting vulnerability.

RaidenFTPD 2.4.4005 Buffer Overflow

RaidenFTPD version 2.4.4005 suffers from a buffer overflow vulnerability.

CMS TSS-EST 1.0.0 SQL Injection

CMS TSS-EST version 1.0.0 from a remote SQL injection vulnerability that allows for authentication bypass.

Foody Friend 1.0 Arbitrary File Upload / Cross Site Scripting

Foody Friend version 1.0 suffers from an arbitrary file upload vulnerability that can assist in cross site scripting attacks.

CMS Supported IRF-TH 2.0.6 Cross Site Scripting

CMS Supported IRF-TH version 2.0.6 suffers from a cross site scripting vulnerability.

Wifi Soft Unibox Administration 3.0 / 3.1 SQL Injection

Wifi Soft Unibox Administration versions 3.0 and 3.1 suffer from a remote SQL injection vulnerability.

CMS SAUDI SOFTECH 5.0.2 SQL Injection

CMS SAUDI SOFTECH version 5.0.2 suffers from a remote SQL injection vulnerability.