Checkmarx CxQL Sandbox bypass (CVE-2014-8778)

2015-09-03 Thread hdau
Checkmarx CxQL Sandbox bypass (CVE-2014-8778) Vendor: Checkmarx - www.checkmarx.com Product: CxSuite Version affected: 7.1.5 and prior Credit: Huy-Ngoc DAU (@ngocdh) of Deloitte Conseil, France Introduction Checkmarx is a static

Merethis Centreon - Unauthenticated blind SQLi and Authenticated Remote Command Execution

2015-07-08 Thread hdau
Merethis Centreon - Unauthenticated blind SQLi and Authenticated Remote Command Execution CVEs: CVE-2015-1560, CVE-2015-1561 Vendor: Merethis - www.centreon.com Product: Centreon Version affected: 2.5.4 and prior Product description: Centreon is the choice of some of the world's largest