Category Archives: Checkpoint

Checkpoint

Weak SSL 3DES Cipher Suites (CVE-2016-2183)

3DES is a widely supported stream cipher often preferred by TLS servers and other servers using encrypted sessions. Recent cryptanalysis results one of which is the SWEET32 exploit biases in the 3DES keystroke to recover repeatedly encrypted plain-texts. As a result 3DES can no longer be seen as providing a sufficient level of security for encrypted sessions.

Mantis Bug Tracker Filter API view_type Cross Site Scripting (CVE-2016-6837)

A cross-site scripting vulnerability exists in the Filter API component of Mantis Bug Tracker. The vulnerability is due to insufficient input validation on the view_type parameter in view_all_bug_page.php. A remote attacker could exploit this vulnerability by enticing authenticated users to click on a crafted link. Successful exploitation could allow the attacker to execute malicious script code in the context of the victim’s browser.

Trend Micro Control Manager AdHocQuery_Processor.aspx SQL Injection

A SQL injection vulnerability has been reported in Trend Micro Control Manager. The vulnerability is due to lack of validation on two parameters in the AdHocQuery_Processor.aspx script. A remote, authenticated attacker could exploit this vulnerability by sending a malicious HTTP request to the target system. Successful exploitation could lead to arbitrary code execution in the security context of the user.