CVE-2024-2069
published 2024-03-01CVE-2024-2069: A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknown function of the file…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.52%
40.6th percentile
A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknown function of the file /endpoint/delete-faq.php. The manipulation of the argument faq leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-255384.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| remyandrade | faq_management_system | — | — |
| sourcecodester | faq_management_system | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2024-20697: Windows Libarchive Remote Code Execution Vulnerability
blogs_trendmicro·2024-04-17·CVSS 7.3
CVE-2024-20697 [HIGH] CVE-2024-20697: Windows Libarchive Remote Code Execution Vulnerability
## CVE-2024-20697: Windows Libarchive Remote Code Execution Vulnerability
Learn about cve-2024-2069 Windows Libarchive remote code execution vulnerability.
By: Trend Micro Research 2024/04/17 Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Guy Lederfein and Jason McFadyen of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in Microsoft Windows. This bug was originally discovered by the Microsoft Offensive Research & Security Engineering team. Successful exploitation could result in arbitrary code execution in the context of the application using the vulnerable library. The following is a portion of their write-up covering CVE-2024-20697, with a few minimal modifications.
Trendmicro
CVE-2024-20697: Windows Libarchive Remote Code Execution Vulnerability
blogs_trendmicro·2024-04-17·CVSS 7.3
CVE-2024-20697 [HIGH] CVE-2024-20697: Windows Libarchive Remote Code Execution Vulnerability
# CVE-2024-20697: Windows Libarchive Remote Code Execution Vulnerability
Learn about cve-2024-2069 Windows Libarchive remote code execution vulnerability.
By: Trend Micro Research
2024/04/17
Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Guy Lederfein and Jason McFadyen of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in Microsoft Windows. This bug was originally discovered by the Microsoft Offensive Research & Security Engineering team. Successful exploitation could result in arbitrary code execution in the context of the application using the vulnerable library. The following is a portion of their write-up covering CVE-2024-20697, with a few minimal modifications.
https://github.com/smurf-reigz/security/blob/main/proof-of-concepts/SOURCECODESTER%20%5BFAQ%20Management%20System%20Using%20PHP%20and%20MySQL%5D%20SQLi%20on%20delete-faq.php.mdhttps://vuldb.com/?ctiid.255384https://vuldb.com/?id.255384https://github.com/smurf-reigz/security/blob/main/proof-of-concepts/SOURCECODESTER%20%5BFAQ%20Management%20System%20Using%20PHP%20and%20MySQL%5D%20SQLi%20on%20delete-faq.php.mdhttps://vuldb.com/?ctiid.255384https://vuldb.com/?id.255384
2024-03-01
Published