Skip to content

トピトピニュース

Header Image

新SD 9.0規格仕様を公開 –セミエンベデッドメモリとしてSDメモリカードの新用途へ

  • Posted inUncategorized
  • Posted byビジネスワイヤ
  • 05/19/2022

新たなセキュリティ機能で対応ホスト機器のブート、セキュアなデータ管理と「保守修理規則」対応 カリフォ…

EPOSの人気ヘッドセット「H6PRO」にサウンドカードとセットのかなりお得な限定モデルが登場!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 05/18/2022

デンマーク コペンハーゲン発のプレミアムゲーミングオーディオブランド「EPOS」配信用のマイクやフル…

JBLのゲーミングヘッドセットから低遅延2.4GHzワイヤレス接続の新モデル「JBL Quantum 350 Wireless」発表!

  • Posted inUncategorized
  • Posted byFunglr Games(日本語)
  • 05/18/2022

ゲームをプレイする際に音は非常に重要な要素の1つです。しかしオーディオの世界は青天井で、突き詰めてい…

[DotNetCasClient] Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/18/202211/23/2022

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrar…

[org.apache.struts:struts2-core] Cross-site Scripting in Apache Struts

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
References

…

[org.apache.struts:struts2-core] Broken Access Control Vulnerability in Apache Struts2

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

The Struts 2 action mapping mechanism supports the special parameter prefix action: which is intended to help with attaching navigational information to buttons within forms, under certain conditions this can be used to bypass security constraints.
In…

[org.apache.portals.jetspeed-2:jetspeed] Path Traversal in Apache Jetspeed

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot do…

[org.apache.portals.jetspeed-2:jetspeed] Cross-site Scripting in Apache Jetspeed

  • Posted inMODERATE
  • Posted byGitHub
  • 05/17/202211/04/2022

Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-0712
https://mail-archives.apache…

[org.apache.tomcat:tomcat] Deserialization of Untrusted Data in Apache Tomcat

  • Posted inHIGH
  • Posted byGitHub
  • 05/17/202211/04/2022

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file…

[org.apache.struts:struts2-core] Remote Code Execution in Apache Struts

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/17/202211/04/2022

XSLTResult allows for the location of a stylesheet being passed as a request parameter. In some circumstances this can be used to inject remotely executable code.
References

https://nvd.nist.gov/vuln/detail/CVE-2016-3082
http://struts.apache.org/docs/…

Posts navigation

Previous Posts 1 … 86,771 86,772 86,773 86,774 86,775 … 86,827 Next Posts

Recent Posts

  • Weather Access
  • BSニュースWorld+Biz
  • シカゴ日本株先物概況・30日 (日本経済新聞)
  • 議員会館捜索、足取り捜査 県議使用の車も押収 (産経新聞)
  • 遠のく非常時ローミングの早期実現。「SIMありアノニマス緊急通報」が今後の鍵か
An error has occurred, which probably means the feed is down. Try again later.
RSS Error: A feed could not be found at `https://nordot.app/-/feed/posts/rss?source_id=646357622673671265&curation_url=true`; the status code is `404` and content-type is `text/html; charset=UTF-8`

What’s Underground News

Underground NewsはオープンRSS情報サイトです。世界中のウェブサイトから情報を収集し、検索のヒントになる情報を掲載しています。登録RSSの追加依頼はこちらから

  • News
  • Twitter
  • Twilog
  • Scrapbox
  • Twitter log
  • Apple News
  • Mastodon log
  • coron news&archives
  • SNSNews
  • TechnoPlanet
  • iTech
  • ComputerJournal
  • Underground News
  • Last.fm
  • はてなブックマーク
  • Tumblr
  • ツイフィール
  • ウェブサイト利用規約
  • Google提供広告の広告設定
  • 他の広告のオプトアウト
  • Valuecommerce配信広告のオプトアウト
  • Zuck配信広告のオプトアウト
  • i-mobile配信広告のオプトアウト
  • Amazon.co.jpパーソナライズド広告の設定
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close