CVE-2015-5019

IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.

CVE-2015-5043

diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences.

CVE-2015-5044

The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 allows remote attackers to cause a denial of service via unspecified packets.

CVE-2015-7412

The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.

CVE-2015-7395

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended work-order change restrictions via unspecified vectors.

Google AdWords API PHP client library <= 6.2.0 Arbitrary PHP Code Execution

Posted by Dawid Golunski on Nov 07

Advisory URL:

http://legalhackers.com/advisories/Google-AdWords-PHP-Client-library-PHP-Code-Execution.txt

=============================================
– Release date: 06.11.2015
– Discovered by: Dawid Golunski
– Severity: Medium/High
=============================================

I. VULNERABILITY
————————-

Google AdWords API PHP client library <= 6.2.0 Arbitrary PHP Code Execution
(googleads-php-lib)

II. BACKGROUND…

Google AdWords API client libraries – XML eXternal Entity Injection (XXE)

Posted by Dawid Golunski on Nov 07

Advisory URL:

http://legalhackers.com/advisories/Google-AdWords-API-libraries-XXE-Injection-Vulnerability.txt

=============================================
– Release date: 06.11.2015
– Discovered by: Dawid Golunski
– Severity: Medium/High
=============================================

I. VULNERABILITY
————————-

Google AdWords API client libraries – XML eXternal Entity Injection (XXE)

Confirmed in googleads-php-lib <=…

Broken, Abandoned, and Forgotten Code, Part 14

Posted by Zach Cutlip on Nov 07

Part 14 of Broken, Abandoned and Forgotten Code is up. In this final
part, we finish discussing post-exploitation. This is really the most
open-ended phase of exploitation, and I discuss a number of creative
things you can do with your target, once compromised. For this post, I
keep it simple with a reverse-TCP root shell. I discuss building the
stage 2 firmware, then flattening it, so the stage 1 firmware can
download and flash it.

Also, this…