exploit the possibilities
Showing 1 - 14 of 14 RSS Feed

Files Date: 2017-03-16

Ubiquiti Networks Command Injection
Posted Mar 16, 2017
Authored by T. Weber | Site sec-consult.com

Various Ubiquiti Networks products suffers from an authenticated command injection vulnerability.

tags | advisory
MD5 | b4522845b8f688284e4281b44509acbe
AXIS Cross Site Request Forgery / Cross Site Scripting
Posted Mar 16, 2017
Authored by David Wearing

Various AXIS cameras suffer from cross site request forgery and cross site scripting vulnerabilities amongst other issues.

tags | exploit, vulnerability, xss, csrf
MD5 | 344e18559669ee5180f333e9216fbb6a
Windows DVD Maker 6.1.7 XXE Injection
Posted Mar 16, 2017
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

Windows DVD Maker version 6.1.7 suffers from an XML external entity injection vulnerability.

tags | exploit, xxe
systems | windows
advisories | CVE-2017-0045
MD5 | 2633411dcb609dcaaf80a71090998e85
Ubuntu Security Notice USN-3235-1
Posted Mar 16, 2017
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3235-1 - It was discovered that libxml2 incorrectly handled format strings. If a user or automated system were tricked into opening a specially crafted document, an attacker could possibly cause libxml2 to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, and Ubuntu 16.04 LTS. It was discovered that libxml2 incorrectly handled certain malformed documents. If a user or automated system were tricked into opening a specially crafted document, an attacker could cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2016-4448, CVE-2016-4658, CVE-2016-5131
MD5 | 29fb4d841313c717c1333135c0ee4970
Slackware Security Advisory - pidgin Updates
Posted Mar 16, 2017
Authored by Slackware Security Team | Site slackware.com

Slackware Security Advisory - New pidgin packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

tags | advisory
systems | linux, slackware
advisories | CVE-2017-2640
MD5 | d1bbad090918734bd156fe55093f530d
Red Hat Security Advisory 2017-0557-01
Posted Mar 16, 2017
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2017-0557-01 - Red Hat JBoss BPM Suite is a business rules and processes management system for the management, storage, creation, modification, and deployment of JBoss rules and BPMN2-compliant business processes. This release of Red Hat JBoss BPM Suite 6.4.2 serves as a replacement for Red Hat JBoss BPM Suite 6.4.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Multiple security issues have been addressed.

tags | advisory
systems | linux, redhat
advisories | CVE-2016-6343, CVE-2016-7034, CVE-2017-2658
MD5 | aa08399474305e9e57e47ad106103eb7
Microsoft Internet Information Services Cross Site Scripting
Posted Mar 16, 2017
Authored by David Fernandez

Microsoft Internet Information Services web server suffers from a cross site scripting vulnerability.

tags | exploit, web, xss
advisories | CVE-2017-0055
MD5 | b0f6fb58b98a9bb87128e9627306c115
Cisco Security Advisory 20170315-tes
Posted Mar 16, 2017
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted URL to the Client Manager Server. An exploit could allow the attacker to retrieve any file from the Cisco Workload Automation or Cisco Tidal Enterprise Scheduler Client Manager Server. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

tags | advisory, remote
systems | cisco
advisories | CVE-2017-3846
MD5 | af82f329130248200b1336e3f5f2352f
WordPress Membership Simplified 1.58 Arbitrary File Download
Posted Mar 16, 2017
Authored by Larry W. Cashdollar

WordPress Membership Simplified plugin version 1.58 suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
MD5 | ffcb9f6436dfbcff266a7a7ac5f9f808
Cisco Security Advisory 20170315-ap1800
Posted Mar 16, 2017
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

tags | advisory, remote, web
systems | cisco
advisories | CVE-2017-3831
MD5 | f6bae90e152cbbf5e0435cc32c45a8d3
Cisco Security Advisory 20170315-asr
Posted Mar 16, 2017
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow an authenticated, remote attacker to gain unrestricted, root shell access. The vulnerability is due to missing input validation of parameters passed during SSH or SFTP login. An attacker could exploit this vulnerability by providing crafted user input to the SSH or SFTP command-line interface (CLI) during SSH or SFTP login. An exploit could allow an authenticated attacker to gain root privileges access on the router. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability can be triggered via both IPv4 and IPv6 traffic. An established TCP connection toward port 22, the SSH default port, is needed to perform the attack. The attacker must have valid credentials to login to the system via SSH or SFTP. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.

tags | advisory, remote, shell, root, tcp
systems | cisco
advisories | CVE-2017-3819
MD5 | b5b7b2652bcc9f39211a3ec6419b9ab3
Microsoft Edge Charkra Incorrect Jit Optimization
Posted Mar 16, 2017
Authored by Google Security Research, lokihardt

Microsoft Edge suffers from a Chakra incorrect jit optimization with TypedArray setter.

tags | exploit
advisories | CVE-2017-0071
MD5 | a505e7581c1060d6b7e275e99be4f682
AppSamvid DLL Hijacking
Posted Mar 16, 2017
Authored by Sachin Wagh

AppSamvid suffers from a dll hijacking vulnerability.

tags | exploit
MD5 | 9700bcaafb038f2c438f2d6a591437cf
Microsoft Edge Undefined Behavior On Getters
Posted Mar 16, 2017
Authored by Google Security Research, lokihardt

Microsoft Edge has some undefined behavior on some getters.

tags | exploit
advisories | CVE-2017-0070
MD5 | 42d3dc0cda6bac79d5dbad5d797e754a
Page 1 of 1
Back1Next

File Archive:

June 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    1 Files
  • 2
    Jun 2nd
    2 Files
  • 3
    Jun 3rd
    19 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    15 Files
  • 6
    Jun 6th
    12 Files
  • 7
    Jun 7th
    11 Files
  • 8
    Jun 8th
    1 Files
  • 9
    Jun 9th
    1 Files
  • 10
    Jun 10th
    15 Files
  • 11
    Jun 11th
    15 Files
  • 12
    Jun 12th
    15 Files
  • 13
    Jun 13th
    8 Files
  • 14
    Jun 14th
    16 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close