Skip to content

Underground News

Header Image

[feedparser] Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in feedparser

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.
References

h…

[pyftpdlib] Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) in pyftpdlib

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having a…

[pyftpdlib] Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) in pyftpdlib

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the getpeername function hav…

[pyftpdlib] Uncontrolled Resource Consumption in pyftpdlib

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Memory leak in the on_dtp_close function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to cause a denial of service (memory consumption) by sending a QUIT command during a data transfer.
References

https://nvd.nist.gov/vu…

[pyftpdlib] Improper Access Control in pyftpdlib

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
References

https://nvd.nist.g…

[org.mortbay.jetty:jetty] Improper input validation in Mort Bay Jetty

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/11/2022

Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window’s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request…

[org.apache.tomcat:tomcat] Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the …war filename.
Referen…

[org.apache.tomcat:tomcat] Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tl…

[org.apache.tomcat:tomcat] Cross-site scripting in Apache Tomcat

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202206/18/2022

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary w…

[org.apache.geronimo.plugins:console] Apache Geronimo Application Server CSRF vulnerabilities

  • Posted inUncategorized
  • Posted byGitHub
  • 05/02/202207/30/2022

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the …

Posts navigation

Previous Posts 1 … 81,147 81,148 81,149 81,150 81,151 … 81,225 Next Posts

Recent Posts

  • カローラ セリカ マークII… 新型クラウンもビックリ!? 超名門トヨタがビッグネームで起こした「大変革」6選 – 自動車情報誌「ベストカー」
  • 5歳~17歳の新型コロナワクチン「接種を推奨」日本小児科学会 | NHK
  • ホラーゲーム『野狗子: Slitterhead』を開発中の外山圭一郎氏・佐藤一信氏とSIEインディーズイニシアチブ代表の吉田修平氏による対談映像が公開。
  • 花粉症に救世主? “エリート秋田杉”とは | NHK | ビジネス特集
  • 韓鶴子「女帝の正体」 13歳で文鮮明に見初められ4回帝王切開 14人出産 | 週刊文春 電子版
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
Underground News
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close