Category Archives: Checkpoint

Checkpoint

GetSimple CMS Arbitrary File Upload

A file upload vulnerability exists in Getsimple CMS v3.3.10. The vulnerability allows authenticated users with low privileged accounts to upload files to the uploads directory. Malicious users can exploit this vulnerability to upload and run arbitrary code from the uploads directory.

Teampass Arbitrary File Upload

A file upload vulnerability exists in Teampass v2.1.26. The vulnerability allows authenticated users with low privileged accounts to upload files to the files directory in the webroot. Malicious users can exploit this vulnerability to upload and run arbitrary code from the files directory.

OpenSSL SSL3_AL_WARNING Denial of Service (CVE-2016-8610)

A denial-of-service vulnerability exists in OpenSSL. The vulnerability, AKA SSL Death Alert, is due to improper handling of warning packets by the function ssl3_read_bytes(). A remote, unauthenticated attacker can exploit this vulnerability by repeatedly sending SSL Alert Warning records during the handshake. Successful exploitation will cause the excessive resource consumption on the server.