Backdoor credentials found in 4 TOTOLINK router models

2015-07-15 Thread Pierre Kim
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 ## Advisory Information Title: Backdoor credentials found in 4 TOTOLINK router models Advisory URL: https://pierrekim.github.io/advisories/2015-totolink-0x03.txt Blog URL: https://pierrekim.github.io/blog/2015-07-16-backdoor-credentials-found-in-4-

4 TOTOLINK router models vulnerable to CSRF and XSS attacks

2015-07-15 Thread Pierre Kim
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 ## Advisory Information Title: 4 TOTOLINK router models vulnerable to CSRF and XSS attacks Advisory URL: https://pierrekim.github.io/advisories/2015-totolink-0x01.txt Blog URL: http://pierrekim.github.io/blog/2015-07-16-4-TOTOLINK-products-vulnerab

15 TOTOLINK router models vulnerable to multiple RCEs

2015-07-15 Thread Pierre Kim
Hash: SHA512 ## Advisory Information Title: 15 TOTOLINK router models vulnerable to multiple RCEs Advisory URL: https://pierrekim.github.io/advisories/2015-totolink-0x00.txt Blog URL: https://pierrekim.github.io/blog/2015-07-16-15-TOTOLINK-products-vulnerable-to-multiple-RCEs.html Date published

Cisco Security Advisory: Cisco Videoscape Delivery System Denial of Service Vulnerability

2015-07-15 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Cisco Security Advisory: Cisco Videoscape Delivery System Denial of Service Vulnerability Advisory ID: cisco-sa-20150715-vds Revision 1.0 For Public Release 2015 July 15 16:00 UTC (GMT

XSS, Code Execution, DOS, Password Leak, Weak Authentication in GetSimpleCMS 3.3.5

2015-07-15 Thread Tim Coen
Vulnerability: XSS, Code Execution, DOS, Password Leak, Weak Authentication Affected Software: GetSimpleCMS (http://get-simple.info/) Affected Version: 3.3.5 (probably also prior versions) Patched Version: 3.3.6 (partial fix) Risk: Medium-High Vendor Contacted: 2015-06-14 Vendor Partial Fix: 2015-0

XSS vulnerability in OFBiz forms

2015-07-15 Thread lilian_iatco
https://issues.apache.org/jira/browse/OFBIZ-6506 In Ofbiz form need to escape characters from description column in a display-entity tag to avoid XSS attacks. I tried to use bsh, as following: But I get this error: Error rendering screen [component://my/widget/CommonScreens.xml#GlobalDecor