[ERPSCAN-16-023] Potential backdoor via hardcoded system ID

2016-08-16 Thread ERPScan inc
Application:SAP АBAP BASIS Versions Affected: SAP АBAP BASIS 7.4 Vendor URL: http://SAP.com Bugs: Hardcoded credentials Sent: 01.02.2016 Reported:

[ERPSCAN-16-022] SAP Hybris E-commerce Suite VirtualJDBC – Default Credentials

2016-08-16 Thread ERPScan inc
Application:SAP Hybris E-commerce Suite Versions Affected: SAP Hybris E-commerce Suite 5.1.0.3 Vendor URL: http://sap.com Bugs: Default credentials Sent:

Lepton CMS PHP Code Injection

2016-08-16 Thread hyp3rlinx
[+] Credits: John Page (HYP3RLINX) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/LEPTON-PHP-CODE-INJECTION.txt [+] ISR: ApparitionSec Vendor: == www.lepton-cms.org Product: = Lepton CMS 2.2.0 /

Lepton CMS Archive Directory Traversal

2016-08-16 Thread hyp3rlinx
[+] Credits: John Page (HYP3RLINX) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/LEPTON-ARCHIVE-DIRECTORY-TRAVERSAL.txt [+] ISR: ApparitionSec Vendor: == www.lepton-cms.org Product: = Lepton CM

[security bulletin] HPSBHF03441 rev.1 - HPE ilO 3 and iLO 4 and iLO 4 mRCA, Remote Multiple Vulnerabilities

2016-08-16 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n a-c05236950 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05236950 Version: 1 HPSBHF03441

[security bulletin] HPSBGN03634 rev.1 - HPE Enterprise Solution Sizers and Storage Sizer running Smart Update, Remote Arbitrary Code Execution

2016-08-16 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n a-c05237578 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05237578 Version: 1 HPSBGN03634

[security bulletin] HPSBST03629 rev.1 - HP StoreFabric B-series Switches, Remote Disclosure of Privileged Information

2016-08-16 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n a-c05236212 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05236212 Version: 1 HPSBST03629

Persistent Cross-Site Scripting in Magic Fields 1 WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Persistent Cross-Site Scripting in Magic Fields 1 WordPress Plugin Burak Kelebek, July 2016 ---

Persistent Cross-Site Scripting in Magic Fields 2 WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Persistent Cross-Site Scripting in Magic Fields 2 WordPress Plugin Burak Kelebek, July 2016 ---

Cross-Site Scripting in Link Library WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Cross-Site Scripting in Link Library WordPress Plugin Burak Kelebek, July 2016

Ajax Load More Local File Inclusion vulnerability

2016-08-16 Thread Summer of Pwnage
Ajax Load More Local File Inclusion vulnerability Burak Kelebek, July 2016 Abs

Cross-Site Scripting/Cross-Site Request Forgery in Peter's Login Redirect WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Cross-Site Scripting/Cross-Site Request Forgery in Peter's Login Redirect WordPress Plugin Yorick Koster, July 2016 ---

Cross-Site Request Forgery vulnerability in Email Users WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Cross-Site Request Forgery vulnerability in Email Users WordPress Plugin Julien Rentrop, July 2016

Cross-Site Scripting vulnerability in Google Maps WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in Google Maps WordPress Plugin Julien Rentrop, July 2016 --

Stored Cross-Site Scripting vulnerability in Photo Gallery WordPress Plugin

2016-08-16 Thread Summer of Pwnage
Stored Cross-Site Scripting vulnerability in Photo Gallery WordPress Plugin Umit Aksu, July 2016 --

Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows deleting of images

2016-08-16 Thread Summer of Pwnage
Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows deleting of images Umit Aksu, July 2016 ---

Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows adding of images

2016-08-16 Thread Summer of Pwnage
Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows adding of images Umit Aksu, July 2016 -

Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows deleting of galleries

2016-08-16 Thread Summer of Pwnage
Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows deleting of galleries Umit Aksu, July 2016