Axis VoIP Manager v2.1.5.7 - Multiple Web Vulnerabilities

2012-09-18 Thread Vulnerability Lab
Title: == Axis VoIP Manager v2.1.5.7 - Multiple Web Vulnerabilities Date: = 2012-09-09 References: === http://www.vulnerability-lab.com/get_content.php?id=686 VL-ID: = 686 Common Vulnerability Scoring System: 2.3 Introduction:

SonicWALL EMail Security 7.3.5 - Multiple Vulnerabilities

2012-09-18 Thread Vulnerability Lab
Title: == SonicWALL EMail Security 7.3.5 - Multiple Vulnerabilities Date: = 2012-08-14 References: === http://www.vulnerability-lab.com/get_content.php?id=543 VL-ID: = 543 Common Vulnerability Scoring System: 3.5 Introduction:

Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities

2012-09-18 Thread Vulnerability Lab
Title: == Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities Date: = 2012-09-06 References: === http://www.vulnerability-lab.com/get_content.php?id=557 VL-ID: = 557 Common Vulnerability Scoring System: 5 Introduction:

[security bulletin] HPSBMU02813 SSRT100712 rev.1 - HP Operations Orchestration, Remote Execution of Arbitrary Code

2012-09-18 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03490339 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03490339 Version: 1 HPSBMU02813

Fortigate UTM WAF Appliance - Cross Site Vulnerabilities

2012-09-18 Thread Vulnerability Lab
Title: == Fortigate UTM WAF Appliance - Cross Site Vulnerabilities Date: = 2012-09-07 References: === http://www.vulnerability-lab.com/get_content.php?id=559 VL-ID: = 559 Common Vulnerability Scoring System: 3.5 Introduction:

APPLE-SA-2012-09-17-1 Apple Remote Desktop 3.5.3

2012-09-18 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2012-09-17-1 Apple Remote Desktop 3.5.3 Apple Remote Desktop 3.5.3 is now available and addresses the following: Apple Remote Desktop Available for: Apple Remote Desktop 3.0 or later Impact: Connecting to a third-party VNC server with

NGS00267 Patch Notification: Symantec Messaging Gateway SSH with backdoor user account

2012-09-18 Thread NCC Group Research
High risk vulnerability in Symantec Messaging Gateway 18 September 2012 Ben Williams of NCC Group has discovered a High risk vulnerability in Symantec Messaging Gateway Impact: Unauthorised SSH access Versions affected: Symantec Messaging Gateway 9.5.3-3 An updated version of the software

NGS00268 Patch Notification: Symantec Messaging Gateway Out-of-band stored XSS - delivered by email

2012-09-18 Thread NCC Group Research
Critical vulnerability in Symantec Messaging Gateway 18 September 2012 Ben Williams of NCC Group has discovered a critical vulnerability in Symantec Messaging Gateway Impact: Out-of-band stored XSS via email Versions affected: Symantec Messaging Gateway 9.5.3-3 An updated version of the

NGS00263 Patch Notification: Symantec Messaging Gateway - Easy CSRF to add a backdoor-administrator

2012-09-18 Thread NCC Group Research
High risk vulnerability in Symantec Messaging Gateway 18 September 2012 Ben Williams of NCC Group has discovered a high risk vulnerability in Symantec Messaging Gateway Impact: Addition of a backdoor administrator via CSRF Versions affected: Symantec Messaging Gateway 9.5.3-3 An updated

NGS00265 Patch Notification: Symantec Messaging Gateway - Unauthenticated detailed version disclosure

2012-09-18 Thread NCC Group Research
Low risk vulnerability in Symantec Messaging Gateway 18 September 2012 Ben Williams of NCC Group has discovered a low risk vulnerability in Symantec Messaging Gateway Impact: Unauthenticated detailed version disclosure Versions affected: Symantec Messaging Gateway 9.5.3-3 An updated

NGS00266 Patch Notification: Symantec Messaging Gateway Arbitrary file download is possible with a crafted URL

2012-09-18 Thread NCC Group Research
Medium risk vulnerability in Symantec Messaging Gateway 18 September 2012 Ben Williams of NCC Group has discovered a Medium risk vulnerability in Symantec Messaging Gateway Impact: Authenticated arbitrary file download Versions affected: Symantec Messaging Gateway 9.5.3-3 An updated

Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability

2012-09-18 Thread irist . ir
a bug in Vbulletin (blog_plugin_useradmin) v4.1.12 that allows to us to occur a Sql Injection on a Remote machin. # # # Exploit Title : Vbulletin (blog_plugin_useradmin) v4.1.12 Sql Injection Vulnerability # # Author: IrIsT.Ir # # Discovered By :