SEC Consult SA-20181009-0 :: Remote Code Execution via XMeye P2P Cloud in Xiongmai IP Cameras, NVRs and DVRs incl. 3rd party OEM devices (CVE-2018-17915, CVE-2018-17917, CVE-2018-17919)

2018-10-09 Thread SEC Consult Vulnerability Lab
SEC Consult also published a blog post regarding the identified security issues with further background information: Blog: https://r.sec-consult.com/xmeye SEC Consult Vulnerability Lab Security Advisory < 2018100

Responsive Filemanager 9.8.1 Reflected Cross Site Scripting (XSS)

2018-10-09 Thread yavuz atlas
I. VULNERABILITY - Responsive Filemanager 9.8.1 Reflected Cross Site Scripting (XSS) II. CVE REFERENCE - CVE-2018-18062 III. VENDOR - https://www.responsivefilemanager.com IV. REFERENCES -

Responsive Filemanager 9.8.1 Authentication Bypass

2018-10-09 Thread yavuz atlas
I. VULNERABILITY - Responsive Filemanager 9.8.1 Authentication Bypass II. CVE REFERENCE - CVE-2018-18061 III. VENDOR - https://www.responsivefilemanager.com IV. REFERENCES -

[SECURITY] [DSA 4313-1] linux security update

2018-10-09 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4313-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso October 08, 2018

CVE Request: Sitepress Multilingual CMS Plugin Unauthenticated Stored XSS

2018-10-09 Thread Rahul Pratap Singh
## FULL DISCLOSURE #Product : Sitepress Multilingual CMS Plugin #Exploit Author : Rahul Pratap Singh #Version : 3.6.3 and Below #Home page Link : https://wpml.org/ #Website: https://0x62626262.wordpress.com #Date : 08/10/2018 Unauthenticated Stored XSS Vulnerability: —- Description:

APPLE-SA-2018-10-08-2 iCloud for Windows 7.7

2018-10-09 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2018-10-08-2 iCloud for Windows 7.7 iCloud for Windows 7.7 is now available and addresses the following: WebKit Available for: Windows 7 and later Impact: Unexpected interaction causes an ASSERT failure Description: A memory corruption

APPLE-SA-2018-10-08-1 iOS 12.0.1

2018-10-09 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2018-10-08-1 iOS 12.0.1 iOS 12.0.1 is now available and addresses the following: VoiceOver Available for: iPhone 5s and later, iPad Air and later, and iPod touch 6th generation Impact: A local attacker may be able to view photos and

[SECURITY] [DSA 4312-1] tinc security update

2018-10-09 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4312-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso October 08, 2018