CVE-2017-5521

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

CVE-2017-5517

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVE-2017-5518

The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.

CVE-2017-5516

Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary web script or HTML via crafted parameters.

CVE-2017-5515

Cross-site scripting (XSS) vulnerability in the user prompt function in GeniXCMS through 0.0.8 allows remote authenticated users to inject arbitrary web script or HTML via tag names.

SEC Consult SA-20170117-0 :: XSS in Recommend Page extension for TYPO3 CMS (pb_recommend_page)

Posted by SEC Consult Vulnerability Lab on Jan 17

SEC Consult Vulnerability Lab Security Advisory < 20170117-0 >
=======================================================================
title: Cross Site Scripting (XSS)
product: Recommend Page extension for TYPO3 CMS (pb_recommend_page)
vulnerable version: <=2.0.3
fixed version: –
CVE number: –
impact: Medium
homepage: https://typo3.org/
found: 2016-10-21…

EuskalHack Security Congress CFP

Posted by Joxean Koret on Jan 17

] EuskalHack Call For Papers / Call For Trainings [

TL;DR: Awesome security conference in Donostia-San Sebastian (Basque
Country) with even more awesome food happening in June 23-24th 2017.
If it sounds great to you, continue reading 😉

Introduction
————

EuskalHack Security Congress Second Edition is coming again, the first
Ethical Hacking association of Basque Country, with the aim of promoting
the community and culture in information…

Multiple RCE in ZyXEL / Billion / TrueOnline routers

Posted by Pedro Ribeiro on Jan 17

Hi,

TrueOnline is a Thai ISP that distributes customised versions of ZyXEL
and Billion routers – customised with vulnerabilities that is.
The routers contain several default administrative accounts and command
injections that can be abused by authenticated and unauthenticated
attackers. Details in the advisory below, which is a copy of
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt
Metasploit modules have…

Reflected Cross-Site Scripting (XSS) in Atlassian Jira Software

Posted by Roberto Soares on Jan 17

=====[ Tempest Security Intelligence -ADV-2/2016 CVE-2016-6285 ]==========

Reflected Cross-Site Scripting (XSS) in Atlassian Jira Software
—————————————————————

Author(s):

– Roberto Soares
– roberto.soares () tempest.com.br

Tempest Security Intelligence – Recife, Pernambuco – Brazil

=====[ Table of Contents ]================================================

1….