Simple Webserver 2.3-rc1 Directory Traversal

2013-01-03 Thread cwggenius
# Exploit Title: Simple Webserver 2.3-rc1 Directory Traversal # Date: 01/02/2013 # Exploit Author: CwG GeNiuS # Vendor Homepage: http://www.pmx.it # Software Link: http://www.pmx.it/download/sws-2.3-rc1-i686.exe # Version: 2.3-rc1 (and earlier) # Tested on: Windows 7 Enterprise SP1 # #Vulnerability

Aastra IP Telephone encrypted .tuz configuration file leakage

2013-01-03 Thread Timo Juhani Lindfors
Aastra IP telephone encrypted .tuz configuration file leakage - Affected products = Aastra 6753i IP Telephone Firmware Version 3.2.2.56 Firmware Release Code SIP Boot Version 2.5.2.1010 Background ==

AST-2012-015: Denial of Service Through Exploitation of Device State Caching

2013-01-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-015 ProductAsterisk SummaryDenial of Service Through Exploitation of Device State Caching

AST-2012-014: Crashes due to large stack allocations when using TCP

2013-01-03 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2012-014 ProductAsterisk SummaryCrashes due to large stack allocations when using TCP