[FD] SSD Advisory – CloudMe Unauthenticated Remote Buffer Overflow

2018-02-13 Thread SecuriTeam SSD
Full report: https://blogs.securiteam.com/index.php/archives/3669 Twitter: @SecuriTeam_SSD Weibo: SecuriTeam_SSD The following advisory describes one (1) vulnerability found in CloudMe. CloudMe is “a file storage service operated by CloudMe AB that offers cloud storage, file synchronization and c

[FD] DSA-2018-024: Dell EMC VMAX Virtual Appliance (vApp) Manager Multiple Vulnerabilities

2018-02-13 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 DSA-2018-024: Dell EMC VMAX Virtual Appliance (vApp) Manager Multiple Vulnerabilities Dell EMC Identifier: DSA-2018-024 CVE Identifier: CVE-2018-1215, CVE-2018-1216 Severity Rating: CVSS Base Score: See below for each CVE. Affected products: De

[FD] RootedCON Security Conference - 1-3 March, Madrid (Spain)

2018-02-13 Thread omarbv
On the occasion of the ninth edition of RootedCON, the most important computer security conference in the country, around 2,000 hackers will meet to discuss new questions and researchs about the cybersecurity world, with its risks and threats. National and international experts have included in th

Re: [FD] SoapUI v5.3.0 Code Execution

2018-02-13 Thread Ismail Doe
Hey, it's actually CVE-2017-16670. Could this be updated? Sorry about that. -Ismail On Tue, Feb 6, 2018 at 2:43 PM, Ismail Doe wrote: > Document Title: > === > SoapUI Arbitrary Code Execution via Malicious Project > > Product Description: > === > SoapUI is the world's mo

[FD] Multiple SQL injection vulnerabilities in dotCMS (2x CVE)

2018-02-13 Thread Elar Lang
Title: Multiple SQL injection vulnerabilities in dotCMS (2x CVE) Credit: Elar Lang / https://security.elarlang.eu Vendor/Product: dotCMS (http://dotcms.com/) Vulnerability: SQL injection Vulnerable version: before 4.1.1. Theoretically would be fixed in 3.7.2 (not released yet) CVE: CVE-2016-10007,

[FD] CVE-2018-6892 CloudMe Sync <= v1.10.9 Unauthenticated Remote Buffer Overflow

2018-02-13 Thread hyp3rlinx
[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/CLOUDME-SYNC-UNAUTHENTICATED-REMOTE-BUFFER-OVERFLOW.txt [+] ISR: Apparition Security [+] SSD Beyond Security Submission: https://blogs.securiteam.com/index