[FD] Stored Cross-site Scripting Vulnerability in Zurmo 3.2.6

2019-07-26 Thread Daniel Bishtawi
Hello, We are informing you about the vulnerabilities in Zurmo 3.2.6. Here are the details: Information Advisory by Netsparker Name: Stored Cross-site Scripting in Zurmo Affected Software: Zurmo Affected Versions: 3.2.6 Homepage: http://zurmo.org Vulnerability: Stored

[FD] Out of Band Code Evaluation Vulnerability in Zurmo 3.2.6

2019-07-26 Thread Daniel Bishtawi
Hello, We are informing you about the vulnerabilities in Zurmo 3.2.6. Here are the details: Information Advisory by Netsparker Name: Out of Band Code Evaluation in Zurmo Affected Software: Zurmo Affected Versions: 3.2.6 Homepage: http://zurmo.org Vulnerability: Out of Band

[FD] Trend Micro Deep Discovery Inspector IDS / Percent Encoding IDS Bypass

2019-07-26 Thread hyp3rlinx
[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-DEEP-DISCOVERY-INSPECTOR-PERCENT-ENCODING-IDS-BYPASS.txt [+] ISR: Apparition Security [Vendor] www.trendmicro.com [Product] Deep Discovery Inspector

[FD] Code Evaluation Vulnerability in Zurmo 3.2.6

2019-07-26 Thread Daniel Bishtawi
Hello, We are informing you about the vulnerabilities in Zurmo 3.2.6. Here are the details: Information Advisory by Netsparker Name: Code Evaluation Vulnerability in Zurmo Affected Software: Zurmo Affected Versions: 3.2.6 Homepage: http://zurmo.org Vulnerability: Code

[FD] Frame Injection Vulnerability in Zurmo 3.2.6

2019-07-26 Thread Daniel Bishtawi
Hello, We are informing you about the vulnerabilities in Zurmo 3.2.6. Here are the details: Information Advisory by Netsparker Name: Frame Injection in Zurmo Affected Software: Zurmo Affected Versions: 3.2.6 Homepage: http://zurmo.org Vulnerability: Frame Injection

[FD] Open Redirection Vulnerability in Zurmo 3.2.6

2019-07-26 Thread Daniel Bishtawi
Hello, We are informing you about the vulnerabilities in Zurmo 3.2.6. Here are the details: Information Advisory by Netsparker Name: Open Redirection Vulnerability in Zurmo Affected Software: Zurmo Affected Versions: 3.2.6 Homepage: http://zurmo.org Vulnerability: Open

[FD] [SYSS-2019-004]: ABUS Secvest (FUAA50000) - Message Transmission - Unchecked Error Condition (CWE-391) (CVE-2019-14261)

2019-07-26 Thread Matthias Deeg
Advisory ID: SYSS-2019-004 Product: ABUS Secvest (FUAA5) Manufacturer: ABUS Affected Version(s): v3.01.01 Tested Version(s): v3.01.01 Vulnerability Type: Message Transmission - Unchecked Error Condition (CWE-391) Risk Level: High Solution Status: Open Manufacturer Notification: 2019-03-02

[FD] APPLE-SA-2019-7-23-3 iCloud for Windows 10.6

2019-07-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2019-7-23-3 iCloud for Windows 10.6 iCloud for Windows 10.6 is now available and addresses the following: libxslt Available for: Windows 10 and later via the Microsoft Store Impact: A remote attacker may be able to view sensitive

[FD] APPLE-SA-2019-7-23-1 iCloud for Windows 7.13

2019-07-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2019-7-23-1 iCloud for Windows 7.13 iCloud for Windows 7.13 is now available and addresses the following: libxslt Available for: Windows 7 and later Impact: A remote attacker may be able to view sensitive information Description: A stack

[FD] Reflected Cross-site Scripting Vulnerability in Zurmo 3.2.6

2019-07-26 Thread Daniel Bishtawi
Hello, We are informing you about the vulnerabilities in Zurmo 3.2.6. Here are the details: Information Advisory by Netsparker Name: Reflected Cross-site Scripting in Zurmo Affected Software: Zurmo Affected Versions: 3.2.6 Homepage: http://zurmo.org Vulnerability: Reflected

[FD] APPLE-SA-2019-7-23-2 iTunes for Windows 12.9.6

2019-07-26 Thread Apple Product Security via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2019-7-23-2 iTunes for Windows 12.9.6 iTunes for Windows 12.9.6 is now available and addresses the following: libxslt Available for: Windows 7 and later Impact: A remote attacker may be able to view sensitive information Description: A