[FD] [CVE-2017-15359] 3CX Phone System - Authenticated Directory Traversal

2017-10-16 Thread Jens Regel
Please disclose, thanks. -- Regards, Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG Title: == 3CX Phone System - Authenticated Directory Traversal Author: === Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG CVE-ID: === CVE-2017-15359 Risk Information: =

[FD] SSD Advisory – ZTE uSmartView DLL Hijacking

2017-10-16 Thread Maor Shwartz
SSD Advisory – ZTE uSmartView DLL Hijacking Full report: *https://blogs.securiteam.com/index.php/archives/3457 * Twitter: @SecuriTeam_SSD Weibo: SecuriTeam_SSD Vulnerability summary The following advisory describes an DLL Hijacking found in ZT

[FD] ESA-2017-122: EMC NetWorker Buffer Overflow Vulnerability

2017-10-16 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2017-122: EMC NetWorker Buffer Overflow Vulnerability EMC Identifier: ESA-2017-122 CVE Identifier: CVE-2017-8022 Severity Rating: CVSSv3 Base Score: 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) Affected products: * EMC NetWorker versions

[FD] ESA-2017-124: EMC Isilon OneFS Reflected Cross Site Scripting Vulnerability

2017-10-16 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2017-124: EMC Isilon OneFS Reflected Cross Site Scripting Vulnerability CVE Identifier: CVE-2017-8024 EMC Identifier: ESA-2017-124 Severity Rating: CVSS Base Score: 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) Affected Products: *EMC