Archive for September, 2015
Posted by deepcore under Security (No Respond)
[webapps] – SAP Netweaver < 7.01 – XML External Entity Injection
Posted by deepcore under Security (No Respond)
[webapps] – h5ai < 0.25.0 – Unrestricted File Upload
Posted by deepcore under Security (No Respond)
[dos] – OS X Regex Engine (TRE) – Integer Signedness and Overflow Issues
Posted by deepcore under Security (No Respond)
[dos] – OS X Regex Engine (TRE) – Stack Buffer Overflow
Posted by deepcore under Security (No Respond)
[webapps] – Air Drive Plus 2.4 – Arbitrary File Upload Vulnerability
Posted by deepcore under Security (No Respond)
Facebook – Cross-Site Request Forgery Vulnerability
Posted by deepcore under exploit (No Respond)
An independent Vulnerability Laboratory Researcher discovered a cross site request forgery vulnerability in the official Facebook.com system web-application. The issue allows attackers to establishe a videocall connection to any facebook user.
Air Drive Plus v2.4 iOS – Arbitrary File Upload Vulnerability
Posted by deepcore under exploit (No Respond)
The Vulnerability Laboratory Research Team discovered an arbitrary file upload web vulnerability in the official Photo Transfer 2 – v1.0 iOS mobile web-application.
[remote] – Konica Minolta FTP Utility 1.0 – Remote Command Execution
Posted by deepcore under Security (No Respond)
[remote] – Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow
Posted by deepcore under Security (No Respond)