Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages injected with JavaScript. When users access the system and open the email, it triggers an XSS (Reflected Cross-site scripting) attack.
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploit this vulnerability to call privileged APIs to acquire information, manipulate or disrupt the functionality of arbitrary electronic locks.
SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information.
Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administrator, can use the management page to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded keys for file access, modification, and cause service disruption.
В этом дайджесте собрали самое интересное с Kickstarter на начало июня. В подборке можно больше узнать про клавиатуру для борьбы с прокрастинацией, бесконечные стикеры для заметок, виртуальную ударную установку, трекер-визитку для приложения «Локатор» от Apple и шариковую ручку, которая автоматически оцифровывает записи. Читать далее
Поскольку, худо ли - бедно, я добился удалённой отладки для надстроек (напомню, так почему-то назвали разработчики «МойОфис» макросы с возможностью использовать пусть и примитивный, но набор контролов и форм), то зачем останавливаться на достигнутом?Теперь передо мной встал…
Понимаю, что заголовок кликбейтный, но именно это произошло со мной. В @RuStore написал некий "владелец формата файла", показал "лицензию" у себя на сайте, где написано, что только он может читать файлы такого формата, а другие должны просить его разрешения. Этого хватило, чтобы заблокировать мне приложение, в котором чтение этого формата - лишь малая часть функционала. Подробнее
Сегодня завершается ЦИПР-2023 — большая ежегодная конференция, которая посвящена трендам отечественных технологий, экономике, бизнесу, взаимному влиянию ИТ и промышленности. В течение трех дней участники ЦИПР — крупные компании и госструктуры — представляли результаты своей…