MidExploit's profile picture. Cyber Threat Updates

MidnightExploit

@MidExploit

Cyber Threat Updates

Pinned

Midnight Exploit #2: December Snapshot & A Glimpse of Cybersecurity in 2025 open.substack.com/pub/jackrobert… Also on Medium link.medium.com/M6kU3aPiHPb


🚨 Beijing Longda Jushang DBShop XSS (CVE-2024-12991): Remote attacker can inject scripts via orderStatus parameter in /home-order. Upgrade & implement input validation. nvd.nist.gov/vuln/detail/CV… #CyberSecurity #XSS


🚨 CubeCart SQL Injection Vulnerability (CVE-2010-1931): Critical flaw allows remote attackers to execute arbitrary SQL commands. Update to patched versions (after 4.3.9). #CyberSecurity #CubeCart


🚨 Improper Interface Design Vulnerability in Huawei Products (CVE-2020-9236): High severity flaw allows attackers to compromise module service. Update to patched versions (FusionCompute 8.0.0.SPC1). #CyberSecurity #Huawei


🚨1000 Projects Daily College Class Work Report Book Vulnerability (CVE-2024-12964): Critical flaw allows SQL injection in user argument of /login.php. 🛡️Update to latest version & implement input sanitization. ⚠️Remote exploitation possible. #Cyber #SQLInjection #1000Projects


🚨code-projects Job Recruitment Vulnerability (CVE-2024-12963): Critical flaw allows SQL injection in add_xp function of /_parse/_all_edits.php. 🛡️Update to latest version & implement proper input sanitization ⚠️Remote exploitation possible. #Cyber #SQLInjection #codeprojects


🚨Apache MINA Vulnerability (CVE-2024-52046):Critical flaw in ObjectSerializationDecoder (≤2.0.26/2.1.9/2.2.3) allows RCE via untrusted deserialization. 🛡️Upgrade to 2.0.27, 2.1.10, or 2.2.4 & configure accepted classes. ⚠️Easy remote exploit possible. #Cyber #RCE #ApacheMINA


This account does not have any followers

United States Trends

Loading...

Something went wrong.


Something went wrong.