[FD] hardwear.io 2019 Call For Papers is Open - USA & Netherlands

2019-04-04 Thread Yuliya Pliavaka
Dear InfoSec Gurus, Hardwear.io Security Conference and Training is a platform for hardware and security community where researchers showcase and discuss their innovative research on attacking and defending hardware. Submission Topics hardwear.io accepts papers on any topic that discusses

[FD] SphereFTP 2.0 Denial Of Service

2019-04-04 Thread Sachin Wagh
#!/usr/bin/python # Exploit Title: SphereFTP Server v2.0 Remote Denial of Service Vulnerability # Date: 2019-31-03 # Exploit Author: Sachin Wagh (@tiger_tigerboy) # Software Link: http://www.menasoft.com/sphereftp/sphereftp_win32_v20.zip # Tested on: Windows 10 64-bit import socket import sys

[FD] DSA-2019-031: Dell EMC IsilonSD Management Server Cross-Site Scripting (XSS) Vulnerabilities

2019-04-04 Thread secure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Dell EMC Product Taxonomy IsilonSD Management Server Role Security Advisory Technically Signed Off by Product ManagementJohn Harr Engineering Team Phillip Nordwall Program Management David Geijsbeek Service Product Lead

[FD] CVE-2019-7727 - JMX/RMI Nice ENGAGE <= 6.5 Remote Command Execution

2019-04-04 Thread Red Timmy Sec -
Description === NICE Engage is an interaction recording platform. The default configuration in versions <= 6.5 (and possible higher) binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers to execute

[FD] Open-Xchange Security Advisory 2019-04-01

2019-04-04 Thread Open-Xchange GmbH via Fulldisclosure
Dear subscribers, we're sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those vulnerabilities. Feel free to join our bug bounty programs (appsuite, dovecot, powerdns) at HackerOne. Yours sincerely, Martin Heiland, Open-Xchange GmbH

[FD] Uniqkey Password Manager 1.14 - Remote Credential Disclosure

2019-04-04 Thread gionreale
> > Uniqkey Password Manager 1.14 contains a vulnerability which causes remote > credential disclosure under certain conditions. > CVE-2019-10676 > > --- > >

[FD] Various vulnerabilities in Lupusec XT2 Plus home alarm system

2019-04-04 Thread Dan Fabian
=== title: Multiple Vulnerabilities product: Lupusec XT2 Plus Main Panel version: Firmware 0.0.2.19E homepage: https://www.lupus-electronics.de/ found: 01/2019