[Full-disclosure] PSFTP v.1.8 Build 921 - Null Pointer (DoS) Vulnerability

2012-04-23 Thread Research
:Program Files (x86)PSFtpPSFtp.exe Picture(s): ../1.png ../2.png Risk: = The security risk of the null pointer (dos) vulnerability is estimated as medium(-). Credits: Vulnerability Laboratory [Research Team

[Full-disclosure] Chengdu Bureau of Commerce - SQL Injection Vulnerability

2012-04-23 Thread Research
of the bureau team has achieved good results ever, won the Chengdu-class team of 28 community agencies large group of 5 km Team finished sixth. (Copy of the Vendor Homepage: http://www.cdmbc.gov.cn/detail.php?tid=236657 ) Abstract: = The Vulnerability Laboratory Research Team discovered

[Full-disclosure] ACC PHP eMail v1.1 - Multiple Web Vulnerabilites

2012-04-15 Thread Research
risk of the persisten input validation vulnerability is estimated as medium. Credits: Vulnerability Research Laboratory -the_storm (the_st...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty

[Full-disclosure] EmbryoCore CMS v1.03 - Multiple Web Vulnerabilities

2012-04-15 Thread Research
(+). Credits: Vulnerability Research Laboratory -Kevin J. (Silent_0x) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

[Full-disclosure] Microsoft Service - Persistent Web Vulnerabilities

2012-04-15 Thread Research
://partners.microsoft.com/PartnerProgram/CreateReference.aspx Solution: = 2012-04-10: Vendor Fix/Patch by Check Risk: = The security risk of the persistent script code injection vulnerability is estimated as medium(+). Credits: Vulnerability Research Laboratory - Benjamin Kunz Mejri

[Full-disclosure] EmbryoCore CMS v1.03 - Multiple Web Vulnerabilities

2012-04-15 Thread Research
(+). Credits: Vulnerability Laboratory [Research Team] -Kevin J. (Silent_0x) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

[Full-disclosure] Microsoft AFKAR Website Service - Cross Site Vulnerabilities

2012-04-15 Thread Research
/))'+invalidparam=' Risk: = The security risk of the non persistent cross site scripting vulnerabilities are estimated as low(+). Credits: Vulnerability Research Laboratory - Mohd. Shadab Siddiqui (gr4yf0x) Disclaimer: === The information provided in this advisory

[Full-disclosure] Siche Search v.0.5 Zerboard - Multiple Web Vulnerabilities

2012-04-15 Thread Research
risk of the sql injection vulnerabilities are estimated as high(+). 1.2 The security risk of the persistent input validation vulnerability is estimated as low(+). Credits: Vulnerability Laboratory [Research Team] -snup (s...@vulnerability-lab.com) Disclaimer

[Full-disclosure] DHTMLX Suite v.3.0 - Multiple Web Vulnerabilities

2012-04-12 Thread Research
/tr/tbody/table/td/tr/tbody Risk: = 1.1 The security risk of the sql injection vulnerability via POST is estimated as high(-). 1.2 The security risk of the persistent input validation vulnerabilities are estimated as medium(+). Credits: Vulnerability Research Laboratory

[Full-disclosure] Netjuke 1.0 RC1 - SQL Injection Vulnerabilities

2012-04-12 Thread Research
Research Team discovered multiple SQL Injection Vulnerabilities on Netjuke v1.0 RC1. Report-Timeline: 2012-04-12: Public or Non-Public Disclosure Status: Published Exploitation-Technique: === Remote Severity: = High Details

[Full-disclosure] Oracle Service Applications - SQL Injection Vulnerabilities

2012-04-12 Thread Research
: = The security risk of the remote sql injection vulnerabilities are estimated as critical. Credits: Vulnerability Research Laboratory - Mohd. Shadab Siddiqui Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims

[Full-disclosure] CRUNCH TV SHOW - Live Stream Security Videos

2012-04-12 Thread Research
formed more secure. In 1997, Benjamin K.M. founded a non-commercial and independent security research group called, Global Evolution - Security Research Group which is still active today. From 2010 to 2011, Benjamin M. and Pim C. (Research Team) identified over 300 zero day vulnerabilities

[Full-disclosure] Crystal Office Suite v1.43 - Buffer Overflow Vulnerability

2012-04-12 Thread Research
Risk: = The security risk of the local buffer overflow vulnerability is estimated as high. Credits: Vulnerability Research Laboratory Team -Julien Ahrens (MrTuxracer) [www.inshell.net] Disclaimer: === The information provided in this advisory is provided

[Full-disclosure] National Center EDU Research - SQL Injection Vulnerability

2012-04-11 Thread Research
Title: == National Center EDU Research - SQL Injection Vulnerability Date: = 2012-04-09 References: === http://www.vulnerability-lab.com/get_content.php?id=415 VL-ID: = 415 Introduction: = The United States Department of Education, also referred to as ED

[Full-disclosure] Matterdaddy Market v1.1 - SQL Injection Vulnerabilities

2012-04-10 Thread Research
+Categoryop=newCategory Risk: = The security risk of the sql injection vulnerabilities is estimated as high(-). Credits: Vulnerability Research Laboratory -Chokri B.A. (Me!ster) Disclaimer: === The information provided in this advisory is provided as it is without

[Full-disclosure] National Center EDU Research - SQL Injection Vulnerability

2012-04-10 Thread Research
Title: == National Center EDU Research - SQL Injection Vulnerability Date: = 2012-04-09 References: === http://www.vulnerability-lab.com/get_content.php?id=415 VL-ID: = 415 Introduction: = The United States Department of Education, also referred to as ED

[Full-disclosure] GroupWare epesiBIM CRM 1.2.1 - Multiple Web Vulnerabilities

2012-04-10 Thread Research
iframe src=a onload='alert(Vunerabilitylab)' = td= Risk: = The security risk of the persistent vulnerability is estimated as meidum(+). Credits: Vulnerability Research Laboratory Team -Chokri B.A. (Me!ster) Disclaimer: === The information provided in this advisory

[Full-disclosure] Microsoft MSDN - Persistent Web Service Vulnerability

2012-04-09 Thread Research
. Copyright © 2012|Vulnerability-Lab -- VULNERABILITY RESEARCH LABORATORY TEAM Website: www.vulnerability-lab.com Mail: resea...@vulnerability-lab.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

[Full-disclosure] Secunia Research: RealNetworks Helix Server Credentials Disclosure Security Issue

2012-04-09 Thread Secunia Research
== Secunia Research 09/04/2012 - RealNetworks Helix Server Credentials Disclosure Security Issue - == Table of Contents Affected

[Full-disclosure] Secunia Research: Helix Server SNMP Master Agent Service Two Denial of Service Vulnerabilities

2012-04-09 Thread Secunia Research
== Secunia Research 09/04/2012 - RealNetworks Helix Server SNMP Master Agent - - Two Denial of Service Vulnerabilities

[Full-disclosure] AnvSoft Any Video Converter 4.3.6 - Multiple Buffer Overflow Vulnerabilities

2012-04-08 Thread Research
Research Laboratory Team - Benjamin Kunz Mejri (Rem0ve) [www.vulnerability-lab.com] Vulnerability Research Laboratory Team - Julien Ahrens (MrTuxracer) [www.inshell.net] (*handshake*) Disclaimer: === The information provided in this advisory is provided as it is without any warranty

[Full-disclosure] idev Game Site CMS v1.0 - Multiple Web Vulnerabilites

2012-04-08 Thread Research
. Credits: Vulnerability Research Laboratory -the_storm (the_st...@mail.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including

[Full-disclosure] osCmax Shop CMS v2.5.1 - Multiple Web Vulnerabilities

2012-04-08 Thread Research
are estimated as medium. 1.2 The security risk of the non persistent (client side) cross site scripting vulnerabilities are estimated as low(+). Credits: Vulnerability Research Laboratory Team - N/A Anonymous Disclaimer: === The information provided in this advisory

[Full-disclosure] CsForum v0.8 - Cross Site Scripting Vulnerability

2012-04-08 Thread Research
onerror=alert(cross-site-scripting2) / title=Site de l'auteur Example : http://alain.lc.free.fr/csforum8/read.php?id=527debut=8 Risk: = The security risk of the client side cross site scripting vulnerability is estimated as low. Credits: Vulnerability Research Laboratory - Chokri

[Full-disclosure] Astaro Command Center v2.x - Multiple Web Vulnerabilities

2012-04-08 Thread Research
vulnerabilities are estimated as medium(+) because they are all located in main areas of the application. Credits: Vulnerability Research Laboratory Team - Benjamin Kunz Mejri (Rem0ve) Disclaimer: === The information provided in this advisory is provided as it is without any warranty

[Full-disclosure] Astaro Security Gateway v7.504 - Multiple Web Vulnerabilities

2012-04-08 Thread Research
beschreibt detailliert die verfügbaren Sicherheitsanwendungen, technischen Einzelheiten und Einsatzszenarien. (Copy of the Vendor Homepage: https://www.astaro.com/de-de/produkte/hardware-appliance/astaro-security-gateway-625) Abstract: = The vulnerability research team discovers

[Full-disclosure] US UF Services EDU Health - File Include Vulnerability

2012-04-08 Thread Research
: = The security risk of the file include vulnerability is estimated as high(+). Credits: Vulnerability Research Laboratory -N/A Anonymous Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all

[Full-disclosure] SmartJobBoard v3.4 b5140 - Multiple Web Vulnerabilites

2012-04-03 Thread Research
=admin2br/ /form scriptdocument.test.submit();/script /html Risk: = 1.1 The security risk of the persisten input validation vulnerability is estimated as medium. 1.2 The security risk of the cross site request forgery vulnerability is estimated as low. Credits: Vulnerability Research

[Full-disclosure] Astaro Command Center v2.x - Multiple Web Vulnerabilities

2012-04-03 Thread Research
vulnerabilities are estimated as medium(+) because they are all located in main areas of the application. Credits: Vulnerability Research Laboratory Team - Benjamin Kunz Mejri (Rem0ve) Disclaimer: === The information provided in this advisory is provided as it is without any warranty

[Full-disclosure] BulletProof FTP Client 2010 - Buffer Overflow Vulnerability

2012-04-02 Thread Research
: = The security risk of the local buffer overflow vulnerability is estimated as high(+). Credits: Vulnerability Research Laboratory -Julien Ahrens (MrTuxracer) [www.inshell.net] Disclaimer: === The information provided in this advisory is provided as it is without any warranty

[Full-disclosure] DirectAdmin v1.403 - Cross Site Scripting Vulnerability

2012-04-02 Thread Research
: = The issue will be addressed by direct-admin development team with the next update. Risk: = The security risk of the client side cross site scripting vulnerability is estimated as low. Credits: Vulnerability Research Laboratory - Dawid Golak (dawid.go...@gmail.com) Disclaimer

[Full-disclosure] Flatnux CMS 2011 08.09.2 - Multiple Web Vulnerabilities

2012-04-01 Thread Research
: Vulnerability Laboratory [Research Team] -the_storm (the_st...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

[Full-disclosure] ME Firewall Analyzer v7.2 - Cross Site Vulnerabilities

2012-04-01 Thread Research
): ../createAnomaly.do ../mindex.do ../index2.do Risk: = The security risk of the client side cross site scripting vulnerabilities is estimated as low(+). Credits: Vulnerability Research Laboratory - N/A Anonymous

[Full-disclosure] Swedish Army Web Database - SQL Injection Vulnerability

2012-04-01 Thread Research
: = The vulnerability can be patched/fixed by parsing the vulnerable kalender id url value request. 2012-03-31: Vendor Fix/Patch by VL Check Risk: = The security risk of the remote sql injection vulnerability is estimated as high(+). Credits: Vulnerability Research Laboratory - N

[Full-disclosure] HITB2011KUL - Skype Vulnerabilities 0Day Exploitation PART 1

2012-04-01 Thread Research
research team in 2011. The presentation will also provide exclusive attack schemes from an attackers point of view which were also used for verification of our findings. Buglist: – Skype 5.3.x 2.2.x 5.2.x – Persistent Cross Site Scripting Vulnerability – Skype 5.3.x 2.2.x 5.2.x – Persistent

[Full-disclosure] Landshop v0.9.2 - Multiple Web Vulnerabilities

2012-03-31 Thread Research
Research Laboratory -the_storm (the_st...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

[Full-disclosure] Bitsmith PS Knowbase 3.2.3 - Buffer Overflow Vulnerability

2012-03-30 Thread Research
) writeFile.close() print [*] File successfully created!; except: print [!] Error while creating file!; Risk: = The security risk of the local buffer overflow vulnerability is estimated as high(-). Credits: Vulnerability Research Laboratory -Julien Ahrens

[Full-disclosure] B2Evolution CMS 4.1.3 - Multiple Web Vulnerabilities

2012-03-29 Thread Research
injection vulnerability is estimated as high(+). 1.2 The security risk of the critical input validation vulnerability is estimated as medium(+). Credits: Vulnerability Research Laboratory -the_storm (the_st...@mail.com) Disclaimer: === The information provided

[Full-disclosure] Barracuda Cloud CC v3.04.015 - Multiple Web Vulnerabilities

2012-03-29 Thread Research
: Vulnerability Research Laboratory - Benjamin Kunz Mejri (Rem0ve) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

[Full-disclosure] Skype 5.8x 5.5x - Corruption Persistent Vulnerability

2012-03-29 Thread Research
) via hotfix and the issue is addressed by skype. Update to Skype v5.8.0.158 Risk: = The security risk of the remote denial of service vulnerability via pointer corruption is estimated as high(-). Credits: Vulnerability Research Laboratory - Benjamin Kunz Mejri (Rem0ve), Alexander

[Full-disclosure] Apple Website Service - SQL Injection Vulnerabilities

2012-03-29 Thread Research
: Vendor Fix/Patch Risk: = The security risk of the remote sql injection vulnerabilities are estimated as critical. Credits: Vulnerability Research Laboratory - Mohd. Shadab Siddiqui (gr4yf0x) Disclaimer: === The information provided in this advisory is provided

[Full-disclosure] Microsoft Bing - Editor Flash Component Vulnerability

2012-03-16 Thread Research
Title: == Microsoft Bing - Editor Flash Component Vulnerability Date: = 2012-03-15 References: === http://www.vulnerability-lab.com/get_content.php?id=449 MSRC ID#1: 12173 MSRC ID#2: 12227 Credits: http://technet.microsoft.com/en-us/security/cc308589 VL-ID: = 449

[Full-disclosure] JPM Article Script 6 - SQL Injection Vulnerability

2012-03-16 Thread Research
... PoC: http://www.jpmalloy.com/blog/index.php?page2=-1%27cid=0 Risk: = The security risk of the SQL Injection Vulnerability is estimated as high(+). Credits: Vulnerability Research Laboratory -the_storm Disclaimer: === The information provided in this advisory

[Full-disclosure] Windows Credentials Editor (WCE) v1.3beta 32bit release

2012-03-10 Thread Amplia Security Research
WCE v1.3beta 32bit released. Download link: http://www.ampliasecurity.com/research/wce_v1_3beta.tgz Changelog: version 1.3beta: March 8, 2012 * Bug fixes * Extended support to obtain NTLM hashes without code injection * Added feature to dump login cleartext passwords stored by the Digest

[Full-disclosure] [Onapsis Security Advisory 2012-03] Oracle JD Edwards SawKernel Arbitrary File Read

2012-02-23 Thread Onapsis Research Labs
information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, a remote

[Full-disclosure] [Onapsis Security Advisory 2012-04] Oracle JD Edwards SawKernel GET_INI Information Disclosure

2012-02-23 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, a remote

[Full-disclosure] [Onapsis Security Advisory 2012-05] Oracle JD Edwards JDENET Multiple Information Disclosure

2012-02-23 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, a remote

[Full-disclosure] [Onapsis Security Advisory 2012-06] Oracle JD Edwards JDENET Large Packets Denial of Service

2012-02-23 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, a remote

[Full-disclosure] [Onapsis Security Advisory 2012-07] Oracle JD Edwards SawKernel SET_INI Configuration Modification

2012-02-23 Thread Onapsis Research Labs
access to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability

[Full-disclosure] [Onapsis Security Advisory 2012-08] Oracle JD Edwards Security Kernel Information Disclosure

2012-02-23 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, a remote

[Full-disclosure] [Onapsis Security Advisory 2012-01] Oracle JD Edwards JDENET Arbitrary File Write

2012-02-23 Thread Onapsis Research Labs
information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well asexclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, a remote

[Full-disclosure] [Onapsis Security Advisory 2012-02] Oracle JD Edwards Security Kernel Remote Password Disclosure

2012-02-23 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well asexclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability

[Full-disclosure] TELUS Security Labs VR - Oracle Java Web Start Command Argument Injection Remote Code Execution

2012-02-15 Thread TELUS Security Labs - Vulnerability Research
date 2012-02-10 TSL acknowledges update 2012-02-14 Vendor releases advisory and patch 2012-02-14 Published TSL advisory 8. Credits Vulnerability Research Team, TELUS Security Labs 9. References CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0500 Vendor: http

[Full-disclosure] Secunia Research: NTR ActiveX Control Four Buffer Overflow Vulnerabilities

2012-01-12 Thread Secunia Research
== Secunia Research 11/01/2012 - NTR ActiveX Control Four Buffer Overflow Vulnerabilities - == Table of Contents Affected Software

[Full-disclosure] Secunia Research: NTR ActiveX Control StopModule() Input Validation Vulnerability

2012-01-12 Thread Secunia Research
== Secunia Research 11/01/2012 - NTR ActiveX Control StopModule() Input Validation Vulnerability - == Table of Contents Affected

[Full-disclosure] Secunia Research: Winamp AVI Parsing Two Integer Overflow Vulnerabilities

2011-12-13 Thread Secunia Research
== Secunia Research 12/12/2011 - Winamp AVI Processing Two Integer Overflow Vulnerabilities - == Table of Contents Affected

[Full-disclosure] Secunia Research: Sterling Trader Data Processing Buffer Overflow Vulnerability

2011-12-13 Thread Secunia Research
== Secunia Research 13/12/2011 - Sterling Trader Data Processing Buffer Overflow Vulnerability - == Table of Contents Affected

[Full-disclosure] Secunia Research: DVR Remote ActiveX Control DVRobot Library Loading Vulnerability

2011-11-17 Thread Secunia Research
== Secunia Research 17/11/2011 - DVR Remote ActiveX Control DVRobot Library Loading Vulnerability - == Table of Contents Affected

[Full-disclosure] Secunia Research: Autonomy Keyview Ichitaro QLST Integer Overflow Vulnerability

2011-10-07 Thread Secunia Research
== Secunia Research 07/10/2011 - Autonomy Keyview Ichitaro QLST Integer Overflow Vulnerability - == Table of Contents Affected

[Full-disclosure] Secunia Research: Autonomy Keyview Ichitaro Text Parsing Buffer Overflow

2011-10-07 Thread Secunia Research
== Secunia Research 07/10/2011 - Autonomy Keyview Ichitaro Text Parsing Buffer Overflow - == Table of Contents Affected Software

[Full-disclosure] Secunia Research: Autonomy Keyview Ichitaro Object Reconstruction Logic Vulnerability

2011-10-07 Thread Secunia Research
== Secunia Research 07/10/2011 - Autonomy Keyview - - Ichitaro Object Reconstruction Logic Vulnerability

[Full-disclosure] Secunia Research: Cyrus IMAPd NTTP Authentication Bypass Vulnerability

2011-10-05 Thread Secunia Research
== Secunia Research 05/10/2011 - Cyrus IMAPd NTTP Authentication Bypass Vulnerability - == Table of Contents Affected Software

[Full-disclosure] Secunia Research: Novell GroupWise Internet Agent TZNAME Parsing Vulnerability

2011-09-27 Thread Secunia Research
== Secunia Research 27/09/2011 - Novell GroupWise Internet Agent TZNAME Parsing Vulnerability - == Table of Contents Affected

[Full-disclosure] Secunia Research: Novell GroupWise Internet Agent HTTP Interface Buffer Overflow

2011-09-27 Thread Secunia Research
== Secunia Research 27/09/2011 - Novell GroupWise Internet Agent HTTP Interface Buffer Overflow - == Table of Contents Affected

[Full-disclosure] [Onapsis Security Advisory 2011-016] SAP WebAS Malicious SAP Shortcut Generation

2011-09-15 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well asexclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, an internal

[Full-disclosure] [Onapsis Security Advisory 2011-014] SAP WebAS Remote Denial of Service

2011-09-15 Thread Onapsis Research Labs
information to SAP. * 2011-01-25: SAP confirms reception of vulnerability submission. * 2011-06-14: SAP releases SAP Note 1553930 fixing the vulnerability. * 2011-09-14: Onapsis releases security advisory. About Onapsis Research Labs === Onapsis

[Full-disclosure] [Onapsis Security Advisory 2011-015] SAP WebAS webrfc Cross-Site Scripting

2011-09-15 Thread Onapsis Research Labs
information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well asexclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business === By exploiting this vulnerability, an internal

[Full-disclosure] Secunia Research: InduSoft ISSymbol ActiveX Control Buffer Overflow Vulnerabilities

2011-09-01 Thread Secunia Research
== Secunia Research 01/09/2011 - InduSoft ISSymbol ActiveX Control Buffer Overflows - == Table of Contents Affected Software

[Full-disclosure] [Onapsis Research Labs] New SAP Security In-Depth issue - The Invoker Servlet: A Dangerous Detour into SAP Java Solutions

2011-07-28 Thread Onapsis Research Labs
Dear colleague, We are happy to announce the fourth issue of the Onapsis SAP Security In-Depth publication. Onapsis' SAP Security In-Depth is a free technical publication leaded by the Onapsis Research Labs with the purpose of providing specialized information about the current and future

[Full-disclosure] Securstar - DriveCrypt - Local Kernel Denial of Service/Memory Disclosure/Privilege Escalation

2011-07-20 Thread Digit Security Research
===ADVISORY=== Advisory: Securstar - DriveCrypt - Local Kernel Denial of Service/Memory Disclosure/Privilege Escalation Advisory ID: DSEC-2011-0001 Author:Neil Kettle, Digit Security Ltd Affected

[Full-disclosure] PR10-11: Multiple XSS injection vulnerabilities and a offsite redirection flaw within HP System Management Homepage (Insight Manager)

2011-05-23 Thread research
PR10-11: Multiple XSS injection vulnerabilities and a offsite redirection flaw within HP System Management Homepage (Insight Manager) Vulnerability found: 6th June 2010 Date Published 20th May 2011 Severity: Medium Description: XSS vulnerabilities have been found within HP System Management;

[Full-disclosure] PR10-15: Multiple XSS flaws within Mitel's AWC (Mitel Audio and Web Conferencing)

2011-05-16 Thread research
PR10-15: Multiple XSS flaws within Mitel's AWC (Mitel Audio and Web Conferencing) Vulnerability found: 21st July 2010 Vendor informed: 26th July 2010 Vulnerability fixed: Severity: High Description: Mitel Audio and Web Conferencing (AWC) are a simple, cost-effective and scalable audio and

[Full-disclosure] PR10-17 Various XSS and information disclosure flaws within KeyFax response management system

2011-05-09 Thread research
PR10-17: Various XSS and information disclosure flaws within KeyFax response management system http://www.omfax.co.uk Vulnerability found: 25th August 2010 Vendor informed: Vulnerability fixed: Severity: Medium/High Description: KeyFax response management system provides professional

[Full-disclosure] PR10-13: Multiple XSS and Authentication flaws within BMC Remedy Knowledge Management

2011-05-05 Thread research
PR10-13: Multiple XSS and Authentication flaws within BMC Remedy Knowledge Management Vulnerability found: 17th July 2010 Vendor informed: Vulnerability fixed: Severity: High Description: BMC Remedy Knowledge Management provides service desk analysts with a knowledge base of easy-to-find

[Full-disclosure] [Onapsis Security Advisory 2011-003] SAP WebAS ITS Mobile Start Service Multiple Vulnerabilities

2011-04-28 Thread Onapsis Research Labs
advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, an internal or external attacker would

[Full-disclosure] [Onapsis Security Advisory 2011-004] SAP WebAS ITS Mobile Test Service Multiple Vulnerabilities

2011-04-28 Thread Onapsis Research Labs
advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, an internal or external attacker would

[Full-disclosure] [Onapsis Security Advisory 2011-005] SAP Enterprise Portal Path Disclosure

2011-04-28 Thread Onapsis Research Labs
, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, an internal or external attacker would be able to obtain sensitive

[Full-disclosure] [Onapsis Security Advisory 2011-006] Oracle JD Edwards JDENET Kernel Denial of Service

2011-04-28 Thread Onapsis Research Labs
, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability, an unauthenticated attacker would be able to remotely

[Full-disclosure] [Onapsis Security Advisory 2011-007] Oracle JD Edwards JDENET Kernel Shutdown

2011-04-28 Thread Onapsis Research Labs
, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences.  1. Impact on Business = By exploiting this vulnerability, an unauthenticated attacker would be able to remotely shutdown

[Full-disclosure] [Onapsis Security Advisory 2011-009] Oracle JD Edwards JDENET SawKernel Remote Password Disclosure

2011-04-28 Thread Onapsis Research Labs
advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences.  1. Impact on Business = By exploiting this vulnerability, a remote unauthenticated attacker might

[Full-disclosure] [Onapsis Security Advisory 2011-010] Oracle JD Edwards JDENET Remote Logging Deactivation

2011-04-28 Thread Onapsis Research Labs
advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences.  1. Impact on Business =  By exploiting this vulnerability, a remote unauthenticated attacker would be able

[Full-disclosure] [Onapsis Security Advisory 2011-011] Oracle JD Edwards JDENET Buffer Overflow

2011-04-28 Thread Onapsis Research Labs
, presentations and new research projects from the Onapsis Research Labs, as well asexclusive access to special promotions for upcoming trainings and conferences.  1. Impact on Business = By exploiting this vulnerability, a remote unauthenticated attacker might be able to access

[Full-disclosure] [Onapsis Security Advisory 2011-012] Oracle JD Edwards JDENET Firewall Bypass

2011-04-28 Thread Onapsis Research Labs
, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences.  1. Impact on Business =  By exploiting this vulnerability, a remote unauthenticated might be able to connect

[Full-disclosure] [Onapsis Security Advisory 2011-013] Oracle JD Edwards JDENET USRBROADCAST Denial of Service

2011-04-28 Thread Onapsis Research Labs
advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences.  1. Impact on Business = By exploiting this vulnerability, an unauthenticated attacker would be able

[Full-disclosure] Various XSS and information disclosure flaws within Adobe ColdFusion administration console (PR10-08)

2011-03-15 Thread research
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-08 PR10-08: Various XSS and information disclosure flaws within Adobe ColdFusion administration console Vulnerability found: 17th April 2010 Vendor informed: 19th April 2010 Vulnerability fixed: 8th February 2011 Severity:

[Full-disclosure] [Onapsis Research Labs] New SAP Security In-Depth issue and Tool - The Silent Threat: SAP Backdoors and Rootkits

2011-03-09 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dear colleague, We are happy to announce the third issue of the Onapsis SAP Security In-Depth publication. Onapsis' SAP Security In-Depth is a free technical publication leaded by the Onapsis Research Labs with the purpose of providing specialized

[Full-disclosure] NSOADV-2011-003: Majordomo2 'help' Command Directory Traversal (Patch Bypass)

2011-03-08 Thread NSO Research
:CVE-2011-0063 Found Date: 03.02.2011 Date Reported: 03.02.2011 Release Date: 19.02.2011 Author: Nikolas Sotiriu Mail: nso-research at sotiriu.de Website:http://sotiriu.de/ Twitter

[Full-disclosure] Data Encryption Systems - DESLock+ - Local Kernel Code Execution/Denial of Service

2011-02-08 Thread Digit Security Research
===ADVISORY=== Advisory: Data Encryption Systems - DESLock+ - Local Kernel Code Execution/Denial of Service Advisory ID: DSEC-2011-0002 Author:Neil Kettle, Digit Security Ltd Affected Software:

[Full-disclosure] TELUS Security Labs VR - Symantec Alert Management System HNDLRSVC Arbitrary Command Execution

2011-01-31 Thread TELUS Security Labs - Vulnerability Research
7. Disclosure Timeline 2009-07-31 Reported to the vendor 2009-08-03 Vendor response 2011-01-26 Coordinated public disclosure 8. Credits Junaid Bohio of Vulnerability Research Team, TELUS Security Labs 9. References CVE: CVE-2010-0110 Vendor: http://www.symantec.com/business

[Full-disclosure] TELUS Security Labs VR - Novell ZENworks Handheld Management ZfHIPCND.exe Buffer Overflow

2011-01-31 Thread TELUS Security Labs - Vulnerability Research
-01-25 Vendor released patches and advisory 2011-01-26 Published TSL advisory 8. Credits Junaid Bohio of Vulnerability Research Team, TELUS Security Labs 9. References CVE: Not available Vendor: http://www.novell.com/support/viewContent.do?externalId=7007663 http://telussecuritylabs.com

[Full-disclosure] TELUS Security Labs VR - Symantec Antivirus Intel Alert Handler Service Denial of Service

2011-01-31 Thread TELUS Security Labs - Vulnerability Research
Coordinated public disclosure 8. Credits Junaid Bohio of Vulnerability Research Team, TELUS Security Labs 9. References CVE: CVE-2010-0111 Vendor: http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisorypvid=security_advisoryyear=2011suid=20110126_01

[Full-disclosure] [Onapsis Security Advisory 2011-001] SAP Management Console Unauthenticated Service Restart

2011-01-12 Thread Onapsis Research Labs
access to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = By exploiting this vulnerability

[Full-disclosure] [Onapsis Security Advisory 2011-002] SAP Management Console Information Disclosure

2011-01-12 Thread Onapsis Research Labs
to beforehand information on upcoming advisories, presentations and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences. 1. Impact on Business = Abusing this functionality, a remote

[Full-disclosure] Silicon Graphics Inc (SGI) - IRIX - Local Kernel Memory Disclosure/Denial of Service

2011-01-10 Thread Digit Security Research
===ADVISORY=== Advisory: Silicon Graphics Inc (SGI) - IRIX - Local Kernel Memory Disclosure/Denial of Service Advisory ID: DSEC-2010-0001 Author:Neil Kettle, Digit Security Ltd Affected Software:

[Full-disclosure] Secunia Research: Microsoft Word LFO Parsing Double-Free Vulnerability

2010-12-23 Thread Secunia Research
== Secunia Research 23/12/2010 - Microsoft Word LFO Parsing Double-Free Vulnerability - == Table of Contents Affected Software

[Full-disclosure] PR10-14 Unauthenticated command execution within Mitel's AWC (Mitel Audio and Web Conferencing)

2010-12-21 Thread research
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-14 PR10-14 Unauthenticated command execution within Mitel's AWC (Mitel Audio and Web Conferencing) Advisory publicly released: Tuesday, 21 December 2010 Vulnerability found: Wednesday, 21 July 2010 Vendor informed: Monday, 26

[Full-disclosure] http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-04

2010-12-21 Thread research
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-04 PR10-04 Directory traversal limited to file validation within Viva thumbs WordPress add-on Advisory publicly released: Tuesday, 21 December 2010 Vulnerability found: Thursday, 4 February 2010 Vendor informed: Monday, 8

[Full-disclosure] Secunia Research: SAP Crystal Reports Print ActiveX Control Buffer Overflow

2010-12-20 Thread Secunia Research
== Secunia Research 14/12/2010 - SAP Crystal Reports Print ActiveX Control Buffer Overflow - == Table of Contents Affected Software

[Full-disclosure] Secunia Research: RealPlayer AAC Spectral Data Parsing Vulnerability

2010-12-20 Thread Secunia Research
== Secunia Research 10/12/2010 - RealPlayer AAC Spectral Data Parsing Vulnerability - == Table of Contents Affected Software

[Full-disclosure] Secunia Research: RealPlayer cook Arbitrary Free Vulnerability

2010-12-20 Thread Secunia Research
== Secunia Research 10/12/2010 - RealPlayer cook Arbitrary Free Vulnerability - == Table of Contents Affected Software

<    1   2   3   4   5   6   7   >