[FD] InvGate Service Desk post-auth SQL injection as non-privileged user

2014-07-09 Thread Brandon Perry
Hi, https://gist.github.com/brandonprry/fc4d396ca7503d49a0f5 Detailed in the above gist is a slew of SQL injections available to an authenticated but non-privileged user in the latest available version (from their website) of InvGate. -- http://volatile-minds.blogspot.com -- blog http://www.vol

[FD] CVE-2014-3418 - OS Command Injection Infoblox Network Automation

2014-07-09 Thread Nate Kettlewell
Product: Network Automation, licensed as: * NetMRI * Switch Port Manager * Automation Change Manager * Security Device Controller Vendor: Infoblox Vulnerable Version(s): 6.4.X.X-6.8.4.X Tested Version: 6.8.2.11 Vendor Notification: May 12th, 2014 Vendor

[FD] FireFox: Lab Mouse Security: Remote Code Execution via Browser (LZO)

2014-07-09 Thread Lee
I know nothing about this, but some friends kept posting a link to this video. I saw nothing about this in the mailing list, so I thought I would post it to see if others have more info. https://www.youtube.com/watch?v=BcCDETzk4zc Published on Jul 8, 2014 Title: Lab Mouse Security: Remote Code

[FD] TxDOT fixes security issues with txtag.org

2014-07-09 Thread David Longenecker
It's nice to see when security issues are resolved. In April, I reported several security concerns to the Texas Department of Transportation, which is responsible for among other things toll roads throughout the state. The concerns had to do with the billing and management website for TXTAG, one o