Subscribe via feed.
Archive for February, 2016

Soso Transfer v1.1 iOS – Denial of Service Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Core Research Team discovered a remote denial of service vulnerability in the official Soso Transfer mobile iOS web-application.

[dos] – yTree 1.94-1.1 – Local Buffer Overflow

Posted by deepcore under Security (No Respond)

yTree 1.94-1.1 – Local Buffer Overflow

Tags: ,

[webapps] – Timeclock Software 0.995 – Multiple SQL Iinjection Vulnerabilities

Posted by deepcore under Security (No Respond)

Timeclock Software 0.995 – Multiple SQL Iinjection Vulnerabilities

Tags: ,

[dos] – Advanced Encryption Package Buffer Overflow – DoS

Posted by deepcore under Security (No Respond)

Advanced Encryption Package Buffer Overflow – DoS

Tags: ,

SimpleView CRM – Client Side Cross Site Web Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a client-side redirect web vulnerability in the official SimpleView CRM web-application.

Getdpd BB #1 – Persistent Web Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Research team discovered an application-side input validation web vulnerability in the official Getpdp online service web-application.

WinImage DLL Hijacking

Posted by deepcore under exploit (No Respond)

WinImage installers suffer from a DLL hijacking vulnerability.

File Hub 3.3 Arbitrary File Upload / Script Insertion

Posted by deepcore under exploit (No Respond)

File Hub version 3.3 suffers from script insertion and remote file upload vulnerabilities.

VMWare Zimbra Mailer Release 8.6.0.GA Replay Attack

Posted by deepcore under exploit (No Respond)

VMWare Zimbra Mailer Release 8.6.0.GA, latest patch and prior versions with DKIM implementation are vulnerable to longterm Mail Replay attacks. If the expiration header is not set, the signature never expires. This means, that the e-mail, perhaps caught while performing a man in the middle attack, can be replayed years after catching it.

OpenXchange User Enumeration

Posted by deepcore under exploit (No Respond)

OpenXchange versions prior to 7.8 suffer from a user folder enumeration vulnerability.