RS232-NET Converter (JTC-200) suffers from cross site request forgery and weak credential management vulnerabilities along with unauthenticated access over telnet.
Monthly Archives: July 2016
CIMA DocuClass ECM CSRF / XSS / SQL Injection
CIMA DocuClass ECM suffers from cross site request forgery, cross site scripting, direct object reference, and remote SQL injection vulnerabilities.
OpenFire 4.0.1 Cross Site Request Forgery / Cross Site Scripting
OpenFire versions 3.10.2 through 4.0.1 suffer from cross site request forgery and cross site scripting vulnerabilities. These issues are similar as findings discovered by hyp3rlinx but leverage different pages.
PrinceXML Wrapper Class Command Injection
Wrapper classes provided by PrinceXML appear to suffer from command injection vulnerabilities.
Silent Circle Killed Their Warrant Canary
HPE Rushes Out Patch For More Than A Year Of OpenSSL Vulns
Brexit Spam Is Spiking
Android 7.0 Nougat Will Stop Ransomware Resetting Passwords
CVE-2016-0906
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.
CVE-2016-1546
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.