Subscribe via feed.
Archive for December, 2021

Auerswald COMpact 8.0B Privilege Escalation

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a vulnerability in the web-based management interface of the Auerswald COMpact 5500R PBX which allows low-privileged users to access passwords of administrative user accounts. Affected versions include 8.0B and below.

runc / libcontainer Bind Mount Sources Insecure Handling

Posted by deepcore under exploit (No Respond)

The recent commit #9c4440 introduces two vulnerabilities to libcontainer that can be exploited by an attacker with partial control over the bind mount sources of a new container.

Auerswald COMpact 8.0B Arbitrary File Disclosure

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a vulnerability in the web-based management interface of the Auerswald COMpact 5500R PBX which allows users with the “sub-admin” privilege to access any files on the PBX’s file system. Versions 8.0B and below are affected.

Auerswald COMpact 8.0B Backdoors

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered several backdoors in the firmware for the Auerswald COMpact 5500R PBX. These backdoors allow attackers who are able to access the web-based management application full administrative access to the device. Versions 8.0B and below are affected.

[webapps] Croogo 3.0.2 – Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

Croogo 3.0.2 – Remote Code Execution (Authenticated)

Tags: ,

[remote] Auerswald COMpact 8.0B – Multiple Backdoors

Posted by deepcore under Security (No Respond)

Auerswald COMpact 8.0B – Multiple Backdoors

Tags: ,

[remote] Auerswald COMpact 8.0B – Arbitrary File Disclosure

Posted by deepcore under Security (No Respond)

Auerswald COMpact 8.0B – Arbitrary File Disclosure

Tags: ,

[remote] Auerswald COMfortel 2.8F – Authentication Bypass

Posted by deepcore under Security (No Respond)

Auerswald COMfortel 2.8F – Authentication Bypass

Tags: ,

[remote] Auerswald COMpact 8.0B – Privilege Escalation

Posted by deepcore under Security (No Respond)

Auerswald COMpact 8.0B – Privilege Escalation

Tags: ,

[local] HCL Lotus Notes V12 – Unquoted Service Path

Posted by deepcore under Security (No Respond)

HCL Lotus Notes V12 – Unquoted Service Path

Tags: ,