WordPress audio playlist functionality is affected by Cross-Site Scripting

2017-03-06 Thread Summer of Pwnage
WordPress audio playlist functionality is affected by Cross-Site Scripting Yorick Koster, July 2016

Sawmill Enterprise v8.7.9 Pass The Hash Authentication Bypass

2017-03-06 Thread hyp3rlinx
[+] Credits: John Page AKA Hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/SAWMILL-PASS-THE-HASH-AUTHENTICATION-BYPASS.txt [+] ISR: ApparitionSec Vendor: === www.sawmill.net Product:

CVE-2016-7955 - Alienvault OSSIM/USM Authentication Bypass

2017-03-06 Thread Peter Lapp
Details === Product: Alienvault OSSIM/USM Vulnerability: Authentication Bypass Author: Peter Lapp, lappsec () gmail com CVE: CVE-2016-7955 Vulnerable Versions: <=5.3.0 Fixed Version: 5.3.1 Vulnerability Details = This vulnerability allows remote attackers to bypass

CVE-2017-6430: Out-of-Bounds Read (DOS) Vulnerability in Ettercap Etterfilter utility

2017-03-06 Thread ddos2me
Document Title: === CVE-2017-6430: Out-of-Bounds Read (DOS) Vulnerability in Ettercap Etterfilter utility Vendor: === Ettercap (http://ettercap.github.io/ettercap/) Product and Versions Affected: == Etterfilter 0.8.2 and possibly prior. Vulnerability

OpenElec: Remote Code Execution Vulnerability through Man-In-The-Middle(CVE-2017-6445)

2017-03-06 Thread Wolfgang
During my research about update mechanisms of open-source software I discovered vulnerabilities in OpenElec. == [ OVERVIEW ] == System affected: OpenElec CVE: CVE-2017-6445 Vulnerable component: auto-update feature Software-Version: 6.0.3, 7.0.1 User-Interaction: Reboot

CVE-2017-6429: Buffer overflow vulnerability in Tcpreplay tcpcapinfo utility

2017-03-06 Thread ddos2me
Document Title: === CVE-2017-6429: Buffer overflow vulnerability in Tcpreplay tcpcapinfo utility Vendor: === Appneta (https://www.appneta.com/) Product and Versions Affected: == Tcpreplay 4.1.2 and possibly prior. Fixed Version: == 4.2.0

EasyCom SQL iPlug Denial Of Service

2017-03-06 Thread hyp3rlinx
[+] Credits: John Page AKA Hyp3rlinX [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/EASYCOM-SQL-IPLUG-DENIAL-OF-SERVICE.txt [+] ISR: ApparitionSec Vendor: easycom-aura.com Product: === SQL iPlug

[SECURITY] [DSA 3801-1] ruby-zip security update

2017-03-06 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3801-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 04, 2017