欧州、iPhoneのUSB-C充電の義務化に向けて前進
Ars Technicaは6月7日(米国時間)、「iPhones will be required …
Zero emissions hydrofoil ‘flying’ workboat launched
Maritime engineers have launched a “world first” commercially viable workboat that “flies” above the water using electric-powered hydrofoils. The eco-friendly vessels deploy the same foiling technology used by America’s Cup racing yachts, with hydrofoi…
[metacalc] Code Injection in metacalc
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript’s Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript’s Function constructor.
Refere…
[francoisjacquet/rosariosis] Cross-site Scripting in RosarioSIS
Cross-site Scripting (XSS) – Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-1997
https://github.com/francoisjacquet/rosariosis/commit/6b22c0b5b40fad891c8cf9e7eeff3e42a35c0bf8
h…
[github.com/emicklei/go-restful/v3] Authorization Bypass Through User-Controlled Key in go-restful
Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-1996
https://github.com/emicklei/go-restful/commit/fd3c327a379ce08c68ef18765bdc925f5d9bad10…
[dolibarr/dolibarr] Cross-site Scripting in Dolibarr
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-30875
https://github.com/mustgundogdu/Research/edit/main/Dolibar_12.0.5-ReflectedXSS,
https://github.com/mustgundogdu/…
[api-res-py] Backdoor in api-res-py
api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-31313
https://github.com/rakeshrkz7/as_api_res/issues/1
https://pypi.org/project/api-res-py/
http://…
“ガリガリ芸人”アンガールズ山根、筋トレで変化!自慢の筋肉で力技に挑戦
6月9日(木)の『アメトーーク!』では、筋トレをはじめて筋肉がついてきたと自己満足しているメンバーが集結する「筋肉ついてウレシイ芸人」が放送される。 スタジオには野田クリスタル(マヂカルラブリー)、おたけ(ジャングルポケ […]
米俳優マコノヘイさん、「責任ある銃所持を」 ホワイトハウスで銃規制訴える
米俳優マシュー・マコノヘイさんが7日、ホワイトハウスの会見場で銃規制の必要性を訴えた。 マコノヘイさ…