CVE-2017-14087 Trend Micro OfficeScan v11.0 and XG (12.0)* Host Header Injection (apparitionsec / hyp3rlinx)

2017-09-29 Thread apparitionsec
[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/CVE-2017-14087-TRENDMICRO-OFFICESCAN-XG-HOST-HEADER-INJECTION.txt [+] ISR: ApparitionSec Vendor: == www.trendmicro.com Product:

[security bulletin] HPESBGN03773 rev.2 - HPE Application Performance Management (BSM), Remote Code Execution

2017-09-29 Thread swpmb . cyber-psrt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://softwaresupport.hpe.com/km/KM02960811 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: KM02960811 Version: 2 HPESBGN03773 rev.2 - HPE Application Performance Mana

CVE-2017-14084 Trend Micro OfficeScan v11.0 and XG (12.0)* CURL (MITM) Remote Code Execution (apparitionsec / hyp3rlinx)

2017-09-29 Thread apparitionsec
[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/CVE-2017-14084-TRENDMICRO-OFFICESCAN-XG-CURL-MITM-REMOTE-CODE-EXECUTION.txt [+] ISR: ApparitionSec Vendor: == www.trendmicro.com

[CVE-2017-9538] Persistent Application Denial of Service

2017-09-29 Thread andys3c
- Vulnerability type: Persistent Application Denial of Service - Credit: Andy Tan CVE ID: CVE-2017-9538 --- Product: SolarWinds Network