[FD] [CVE-2017-15359] 3CX Phone System - Authenticated Directory Traversal

2017-10-16 Thread Jens Regel
Please disclose, thanks. -- Regards, Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG Title: == 3CX Phone System - Authenticated Directory Traversal Author: === Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG CVE-ID: === CVE-2017-15359 Risk Information:

[FD] ESA-2017-124: EMC Isilon OneFS Reflected Cross Site Scripting Vulnerability

2017-10-16 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2017-124: EMC Isilon OneFS Reflected Cross Site Scripting Vulnerability CVE Identifier: CVE-2017-8024 EMC Identifier: ESA-2017-124 Severity Rating: CVSS Base Score: 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) Affected Products: *EMC

[FD] SEC Consult SA-20171016-0 :: Multiple vulnerabilities in Micro Focus VisiBroker C++

2017-10-16 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20171016-0 > === title: Multiple vulnerabilities product: Micro Focus VisiBroker C++ vulnerable version: 8.5 SP2 fixed version: 8.5 S