[KIS-2018-08] SugarCRM (Web Logic Hooks module) Path Traversal Vulnerability

2018-12-31 Thread Egidio Romano
-- SugarCRM (Web Logic Hooks module) Path Traversal Vulnerability -- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.5.0, 8.0.2,

[KIS-2018-07] SugarCRM (Web Logic Hooks module) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
-- SugarCRM (Web Logic Hooks module) PHP Code Injection Vulnerability -- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to

[KIS-2018-05] SugarCRM (SaveDropDown) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
SugarCRM (SaveDropDown) PHP Code Injection Vulnerability [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0. [-]

[KIS-2018-06] SugarCRM (addLabels) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
- SugarCRM (addLabels) PHP Code Injection Vulnerability - [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0. [-]

[KIS-2018-03] SugarCRM (portal_get_related_notes) SQL Injection Vulnerability

2018-12-31 Thread Egidio Romano
--- SugarCRM (portal_get_related_notes) SQL Injection Vulnerability --- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.4.0 and

[KIS-2018-04] SugarCRM (ConnectorsController) Server-Side Request Forgery Vulnerability

2018-12-31 Thread Egidio Romano
- SugarCRM (ConnectorsController) Server-Side Request Forgery Vulnerability - [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All

[KIS-2018-02] SugarCRM (WorkFlow module) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
--- SugarCRM (WorkFlow module) PHP Code Injection Vulnerability --- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.4.0 and 7.11.0.0.

[KIS-2018-01] Oracle Application Express (AnyChart) Flash-based Cross-Site Scripting Vulnerability

2018-12-31 Thread Egidio Romano
Oracle Application Express (AnyChart) Flash-based Cross-Site Scripting Vulnerability [-] Software Link:

Asserts considered harmful (or GMP spills its sensitive information)

2018-12-31 Thread Jeffrey Walton
The GMP library uses asserts to crash a program at runtime when presented with data it did not anticipate. The library also ignores user requests to remove asserts using Posix's -DNDEBUG. Asserts are a debugging aide intended for developement, and using them in production software ranges from

[security bulletin] MFSBGN03838 rev.1 - UCMDB Configuration Management Service, Multiple Vulnerabilities

2018-12-31 Thread security-alert
Note: the current version of the following document is available here: https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03309650 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: KM03309650 Version: 1 MFSBGN03838 rev.1 - UCMDB Configuration Management Service,