[FD] XSS in Sencha Ext JS 4 to 6

2018-07-02 Thread Daniel Fritsch
A XSS vulnerability exists in the getTip() method of Action Columns. The Ext JS framework brings no built-in XSS protection, meaning that developers are responsible for sanitizing their output. However. the method above takes HTML-escaped data and un-escapes it. Therefore if the tooltip contains

[FD] ntop-ng < 3.4.180617 - Authentication bypass / session hijacking

2018-07-02 Thread Ioannis Profetis
ntop-ng Authentication bypass (CVE-2018-12520) # Product Details ntopng is the next generation version of the original ntop, a network traffic probe that shows the network usage, similar to what the popular top Unix command does. ntopng is based on libpcap and it has been written in a portable

[FD] XXE in WeChat Pay Sdk ( WeChat leave a backdoor on merchant websites)

2018-07-02 Thread Rose Jackcode
Hi List, [Title] XXE in WeChat Pay Sdk ( WeChat leave a backdoor on merchant websites) -- [Background] “Mobile payments surge to $9 trillion a year, changing how people shop, borrow—even panhandle”, as WSJ.com once reported. As a payment

[FD] DSA-2018-122: RSA Certificate Manager Path Traversal Vulnerability

2018-07-02 Thread Dell EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 DSA-2018-122: RSA Certificate Manager Path Traversal Vulnerability Dell EMC Identifier: DSA-2018-122 CVE Identifier: CVE-2018-11051 Severity: High Severity Rating: CVSS v3 Base Score: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Affected

[FD] Significant Vulnerabilities in Axis IP Cameras

2018-07-02 Thread Vulnerability Report
Hello, We have discovered and responsibly disclosed seven vulnerabilities affecting 390 Axis IP Camera models. Chaining three of these vulnerabilities together, allows an unauthenticated attacker to execute commands on the cameras as root over the network. A technical blog post with the

[FD] APPLE-SA-2018-06-27-1 SwiftNIO 1.8.0

2018-07-02 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 APPLE-SA-2018-06-27-1 SwiftNIO 1.8.0 SwiftNIO 1.8.0 is now available and addresses the following: SwiftNIO Available for: macOS Sierra 10.12 and later, Ubuntu 14.04 and later Impact: A remote attacker may be able to overwrite arbitrary memory

Re: [FD] Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction

2018-07-02 Thread okan coskun
# Exploit Title: Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction # Vendor Homepage: https://www.microsoft.com/ # Version: 2010 # CVE : CVE-2018-12571 # MSRC: Case 39000 # Proof of Concept #1 Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to

[FD] Double free in openslp 2.0.0

2018-07-02 Thread Magnus Klaaborg Stubman
Reference: https://dumpco.re/blog/openslp-2.0.0-double-free 2018-06-28 SLPD DOUBLE FREE An issue was found in openslp-2.0.0 that can be used to induce a double free bug or memory corruption by corrupting glibc's doubly-linked memory chunk list. On line 409 of slpd_process.c,

[FD] CVE-2018-12103

2018-07-02 Thread Kevin R
> [Suggested description] > An issue was discovered on D-Link DIR-890L A2 devices. > Due to the predictability of the /docs/captcha_(number).jpeg URI, > being local to the network, but unauthenticated to the administrator's > panel, an attacker can disclose the CAPTCHAs used by the access point >

[FD] KL-001-2018-008 : HPE VAN SDN Unauthenticated Remote Root Vulnerability

2018-07-02 Thread KoreLogic Disclosures
KL-001-2018-008 : HPE VAN SDN Unauthenticated Remote Root Vulnerability Title: HPE VAN SDN Unauthenticated Remote Root Vulnerability Advisory ID: KL-001-2018-008 Publication Date: 2018.06.25 Publication URL: https://korelogic.com/Resources/Advisories/KL-001-2018-008.txt 1. Vulnerability Details

[FD] Open-Xchange Security Advisory 2018-07-02

2018-07-02 Thread Open-Xchange GmbH
Product: OX App Suite Vendor: OX Software GmbH Internal reference: 58055 (Bug ID) Vulnerability type: XEE (CWE-611) Vulnerable version: 7.8.4 Vulnerable component: office Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 7.6.3-rev37, 7.8.2-rev40, 7.8.3-rev48,

[FD] Faraday Beta V3.0 Released

2018-07-02 Thread Francisco Amato
Faraday helps you to host your own vulnerability management platform now and streamline your team in one place. We are pleased to announce the newest version of Faraday v3.0. In this new version we have made major architecture changes to adapt our software to the new challenges of cyber security.

[FD] [CVE-2018-8755] Nucom NC-WR644GACV Auth Bypass

2018-07-02 Thread Fernando A. Lagos Berardi
Overview Researchers of NVEL4 Cybersecurity company have discovered that it is possible to access to the config file bypassing admin authentication and authorization. The vulnerability has been reported to the vendor. The vendor has confirmed the vulnerability but not issued to security

[FD] Windows Kernel (win32k.sys) Local Denial Of Service

2018-07-02 Thread Victor Portal Gonzalez
Hello, It is possible to trigger a BSOD caused by a Null pointer deference when calling the system call NtUserConsoleControl with the following arguments: - NtUserControlConsole(1,0,8). - NtUserControlConsole(4,0,8). - NtUserControlConsole(6,0,12). - NtUserControlConsole(2,0,12).