Subscribe via feed.
Archive for April, 2020

haproxy hpack-tbl.c Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

The haproxy hpack implementation in hpack-tbl.c handles 0-length HTTP headers incorrectly. This can lead to a fully controlled relative out-of-bounds write when processing a malicious HTTP2 request (or response).

Mahara 19.10.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Mahara version 19.10.2 suffers from a persistent cross site scripting vulnerability.

Sky File 2.1.0 Cross Site Scripting / Directory Traversal

Posted by deepcore under exploit (No Respond)

Sky File version 2.1.0 for iOS suffers from cross site scripting and directory traversal vulnerabilities.

QRadar Community Edition 7.3.1.6 Default Credentials

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 is deployed with a default password for the ConfigServices account. Using this default password it is possible to download configuration sets containing sensitive information, including (encrypted) credentials and host tokens. With these host tokens it is possible to access other parts of QRadar.

QRadar Community Edition 7.3.1.6 Server Side Request Forgery

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 has an issue where the RssFeedItem class of the QRadar web application is used to fetch and parse RSS feeds. No validation is performed on the user-supplied RSS feed URL. Due to the lack of URL validation (whitelisting), it is possible for authenticated attackers to execute Server-Side Request Forgery attacks. […]

QRadar Community Edition 7.3.1.6 CSRF / Weak Access Control

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 suffers from cross site request forgery and weak access control vulnerabilities.

QRadar Community Edition 7.3.1.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 suffers from a reflective cross site scripting vulnerability in the Forensics link analysis page.

QRadar Community Edition 7.3.1.6 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 suffers from a local privilege escalation due to insecure file permissions with run-result-reader.sh.

QRadar Community Edition 7.3.1.6 PHP Object Injection

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 suffers from a php object injection vulnerability.

QRadar Community Edition 7.3.1.6 Arbitrary Object Instantiation

Posted by deepcore under exploit (No Respond)

QRadar Community Edition version 7.3.1.6 is vulnerable to instantiation of arbitrary objects based on user-supplied input. An authenticated attacker can abuse this to perform various types of attacks including server-side request forgery and (potentially) arbitrary execution of code.