ShoreTel Connect ONSITE versions 20.xx.xxxx.x and 21.xx.xxxx.x up to 21.79.4311.0 suffer from an unauthenticated remote blind SQL injection vulnerability.
Monthly Archives: September 2016
EKG Gadu 1.9~pre+r2855-3+b1 Local Buffer Overflow
EKG Gadu versions 1 through 1.9~pre+r2855-3+b1 suffer from a local buffer overflow vulnerability.
CodeCanyon iBilling 2.4 Cross Site Scripting
CodeCanyon iBilling version 2.4 suffers from a cross site scripting vulnerability.
MetInfo 3.0 SQL Injection
MetInfo version 3.0 suffers from a remote SQL injection vulnerability.
ECShop 2.7.2 Open Redirect
ECShop version 2.7.2 suffers from an open redirection vulnerability.
Coupon CMS 5.00 Open Redirect
Coupon CMS version 5.00 suffers from an open redirection vulnerability.
VMWare Workstation vprintproxy.exe JPEG2000 Handling Memory Corruption
VMWare Workstation vprintproxy.exe suffers from multiple memory corruption and other crashes in the handling of JPEG2000 images.
Unrestricted Upload/RCE in Neosense theme for WordPress
Posted by Walter Hop on Sep 19
Unrestricted Upload/RCE in Neosense theme for WordPress
https://lifeforms.nl/20160919/unrestricted-upload-neosense <https://lifeforms.nl/20160919/unrestricted-upload-neosense>
Vulnerability:
Neosense is a WordPress theme by dynamicpress.
(https://themeforest.net/item/neosense-multipurpose-wordpress-theme/6363229
<https://themeforest.net/item/neosense-multipurpose-wordpress-theme/6363229>)
Neosense theme version 1.7 contains an…
Segmentation fault in Oracle Outside In File ID 8.5.3
Posted by Brandon Perry on Sep 19
This is a segfault in the Oracle Outside In File ID library version 8.5.3.
http://www.oracle.com/technetwork/middleware/content-management/downloads/oit-dl-otn-097435.html
==22240== Memcheck, a memory error detector
==22240== Copyright (C) 2002-2015, and GNU GPL’d, by Julian Seward et al.
==22240== Using Valgrind-3.11.0 and LibVEX; rerun with -h for copyright info
==22240== Command: ./fisimple…
Facebook Privacy Issue – IRL Direct Human Reference
Posted by Hicham A. Tolimat on Sep 19
Oh hai o/
TL;DR:
This is not your usual full disclo delivery.
it’s a 4chan-style lampoon, or what we could call in French “un pamphlet
2.0″.
Excuse my French, Kudos for challenging/improving my English.
If you’re only interested in technicalities, this “vuln” can be written
down to:
“FB Search/AI Injection” using “English, M**, do you speak it?”
-> Insecure Direct Object Reference +…