[FD] Multiple issues in Teracue ENC-400 including pre-authenticated remote code execution

2019-02-21 Thread Stephen Shkardoon
Introduction Multiple vulnerabilities were identified within the Teracue ENC-400, including pre-authenticated remote code authentication. While the vendor has released updated firmware after these issues were identified, they are not all resolved with the latest version of the

[FD] [CVE-2019-8938] Cross Site Scripting in VertrigoServ 2.17

2019-02-21 Thread Rafael Pedrero
___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [CVE-2018-18845] Cross Site Scripting in Advanced comment system v1.0

2019-02-21 Thread Rafael Pedrero
I thought I had reported it but not, better late than never. ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [CVE-2019-8925 to CVE-2019-8929] Path traversal and Cross Site Scripting in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 Administration zone

2019-02-21 Thread Rafael Pedrero
___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [CVE-2019-8923, CVE-2019-8924] SQL injection and persistent Cross Site Scripting in XAMPP 5.6.8 (and previous)

2019-02-21 Thread Rafael Pedrero
___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] CA20190212-01: Security Notice for CA Privileged Access Manager

2019-02-21 Thread Kevin Kotas via Fulldisclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CA20190212-01: Security Notice for CA Privileged Access Manager Issued: February 12, 2019 Last Updated: February 12, 2019 CA Technologies Support is alerting customers to a potential risk with CA Privileged Access Manager. A vulnerability exists

Re: [FD] Reflected Cross-site Scripting Vulnerability in Collabtive 3.1

2019-02-21 Thread Henri Salo
On Wed, Jan 30, 2019 at 09:28:15AM +0100, Daniel Bishtawi wrote: > https://www.netsparker.com/web-applications-advisories/ns-18-052-reflected-cross-site-scripting-in-collabtive/ CVE-2019-8935 has been assigned for this vulnerability. -- Henri Salo

[FD] Open Redirection Vulnerability in GetSimpleCMS 3.3.13

2019-02-21 Thread Daniel Bishtawi
Hello, We are glad to inform you about the vulnerabilities we reported in GetSimpleCMS 3.3.13. Here are the details: Advisory by Netsparker Name: Open Redirection Vulnerability in GetSimpleCMS Affected Software: GetSimpleCMS Affected Versions: 3.3.13 Homepage: http://get-simple.info/

[FD] [SAUTH-2019-0001] - Micro Focus Filr Multiple Vulnerabilities

2019-02-21 Thread advisories
SecureAuth - SecureAuth Labs Advisory http://www.secureauth.com/ Micro Focus Filr Multiple Vulnerabilities 1. *Advisory Information* Title: Micro Focus Filr Multiple Vulnerabilities Advisory ID: SAUTH-2019-0001 Advisory URL: