Screen SFT DAB 600/C Unauthenticated Information Disclosure (userManager.cgx)

Title: Screen SFT DAB 600/C Unauthenticated Information Disclosure (userManager.cgx) Advisory ID: [ZSL-2023-5776]() Type: Local/Remote Impact: Spoofing, Exposure of System Information, Exposure of Sen ...

Continue Reading
Screen SFT DAB 600/C Authentication Bypass Admin Password Change Exploit

Title: Screen SFT DAB 600/C Authentication Bypass Erase Account Exploit Advisory ID: [ZSL-2023-5774]() Type: Local/Remote Impact: Privilege Escalation, Security Bypass, DoS Risk: (4/5) Release Date: 1 ...

Continue Reading
Screen SFT DAB 600/C Authentication Bypass Account Creation Exploit

Title: Screen SFT DAB 600/C Authentication Bypass Account Creation Exploit Advisory ID: [ZSL-2023-5771]() Type: Local/Remote Impact: Privilege Escalation, Security Bypass Risk: (4/5) Release Date: 13. ...

Continue Reading
Screen SFT DAB 600/C Authentication Bypass Reset Board Config Exploit

Title: Screen SFT DAB 600/C Authentication Bypass Reset Board Config Exploit Advisory ID: [ZSL-2023-5775]() Type: Local/Remote Impact: Privilege Escalation, Security Bypass, DoS Risk: (3/5) Release Da ...

Continue Reading
Screen SFT DAB 600/C Authentication Bypass Password Change Exploit

Title: Screen SFT DAB 600/C Authentication Bypass Password Change Exploit Advisory ID: [ZSL-2023-5772]() Type: Local/Remote Impact: Privilege Escalation, Security Bypass Risk: (4/5) Release Date: 13.0 ...

Continue Reading
CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease whe ...

Continue Reading
New Phishing-as-a-Service Platform Lets Cybercriminals Generate Convincing Phishing Pages

[![phishing-as-a-service](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() A new phishing-as-a-service (PhaaS or PaaS) platform na ...

Continue Reading
Information Disclosure

ghost is vulnerable to Information Disclosure. The vulnerability exists because the library does not properly validate the public API endpoints when filtering, which allows an attacker to reveal priva ...

Continue Reading

Back to Main

Subscribe for the latest news: