This Metasploit module exploits a buffer overflow on the Supermicro Onboard IPMI controller web interface. The vulnerability exists on the close_window.cgi CGI application, and is due to the insecure usage of strcpy. In order to get a session, the module will execute system() from libc with an arbitrary CMD payload sent on the User-Agent header. This Metasploit module has been tested successfully on Supermicro Onboard IPMI (X9SCL/X9SCM) with firmware SMT_X9_214.
3db49add914cadb4e6f7130ba3b4a6a1c8c69c567c9d6a7d82b5980b09616017
Elastix version 2.4.0 suffers from multiple cross site scripting vulnerabilities.
509909bae460646e9c79ae511e3c817214b4574939b7672fc3723d3773259720
Limonade Framework version 3.0 suffers from a local file disclosure vulnerability.
443d4ee19f551464d8ebd684cb014326802ade98ba48a5bd76668b40540b2616
Debian Linux Security Advisory 2795-2 - It was discovered discovered that SSL connections with client certificates stopped working after the DSA-2795-1 update of lighttpd. An upstream patch has now been applied that provides an appropriate identifier for client certificate verification.
6ea08a640d945842f0d2904e7fd354564b3f05ed8e6a0b71145488693257820b
WordPress Euclid theme suffers from a cross site request forgery vulnerability.
49fde0a1248fb3f261935e7861a803f31c5996379e540c4452c31d2caa41d47d
WordPress Dimension theme suffers from a cross site request forgery vulnerability.
c79f4bdf46ea63e7957d6c6e13d78d30ac7c626decaf17605d13c77d8d8b5370
WordPress Amplus theme suffers from a cross site request forgery vulnerability.
90cdcb8d4e659c08cee7021e9bc9fa3135983a4188217e174de3a055e42dd6f1
WordPress Make A Statement theme suffers from a cross site request forgery vulnerability.
bc164cec434beccdd48ac4cb8f5fac9449eb0916b078caa972f7ac7fe5464bbc