CVE-2015-6576: Bamboo - Deserialisation resulting in remote code execution

2015-10-23 Thread David Black
Note: the current version of this advisory can be found at https://confluence.atlassian.com/x/Hw7RLg . CVE ID: CVE-2015-6576 Product: Bamboo. Affected Bamboo product versions: * 2.2 <= version < 5.8.5 * 5.9.0 <= version < 5.9.7 Summary: This advisory discloses a critical severity security vuln

Re: TeamSpeak Client <= 3.0.18.1 RFI, Directory Traversal to RCE

2015-10-23 Thread scurippio
Encoding correction : Exploit Title: "PwnSpeak" a 0day Exploit for TeamSpeak Client <= 3.0.18.1 RFI to RCE Date: 12/10/2015 Author: Scurippio / (0x6FB30B11 my pgp keyid) Vendor Homepage: https://www.teamspeak.com/ Application: TeamSpeak 3 Version: TeamSpeak3 Client 3.0.0 - 3.0.18.1 Platform

SEC Consult SA-20151022-0 :: Lime Survey Multiple Critical Vulnerabilities

2015-10-23 Thread SEC Consult Vulnerability Lab
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SEC Consult Vulnerability Lab Security Advisory < 20151022-0 > === title: Multiple critical vulnerabilities product: Lime Survey vulnerable version: 2.05 up

Re: TeamSpeak Client <= 3.0.18.1 RFI, Directory Traversal to RCE

2015-10-23 Thread scurippio
Without encoding error... Exploit Title: "PwnSpeak" a 0day Exploit for TeamSpeak Client <= 3.0.18.1 RFI to RCE Date: 12/10/2015 Author: Scurippio / (0x6FB30B11 my pgp keyid) Vendor Homepage: https://www.teamspeak.com/ Application: TeamSpeak 3 Version: TeamSpeak3 Client 3.0.0 - 3.0.18.1 Plat