CVE-2015-5659

SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Re: WinRAR SFX v5.21 – Remote Code Execution Vulnerability

Posted by Stefan Kanthak on Oct 10

“Shawn McMahon” syberghost () gmail com wrote:

1. installation <> execution;
2. installation of a package does NOT require administrative rights in
general!

No!
The point is: well-known package formats allow you to inspect “things”,
EXE generally dont.
In more detail:

1. It’s not a vulnerability, but a weakness and (design) bug in the first
place: there is no need to EXEcute programs from (possibly)…

Writing Cisco IOS Rootkits

Posted by Luca on Oct 10

This paper is about the work involved in modifying firmware images with
the test case focused on Cisco IOS. It will show how it is a common
misconception that doing such a thing involves advanced knowledge or
nation state level resources. This paper provides sound methodologies,
shows how to approach the subject, and walks the reader through the
entire process while providing the necessary knowledge so that by the
end of the paper, if the…