Category Archives: Checkpoint

Checkpoint

Microsoft Edge Security Feature Bypass (MS17-007: CVE-2017-0140)

Security feature bypass exists in Microsoft Edge. The vulnerability is due to a breach in the way Microsoft Edge implements SOP (Same Origin Policy) for HTML elements present in other browser windows. A remote attacker could exploit this vulnerability by enticing a user to visit a maliciously crafted web-page. Successful exploitation of this vulnerability would allow an attacker to bypass the same origin policy and disclose sensitive information.

Advantech WebAccess updateTemplate.aspx SQL Injection (CVE-2017-5154)

An SQL injection vulnerability has been reported in Advantech WebAccess. The vulnerability is due to insufficient validation of the template parameter in HTTP request sent to the updateTemplate.aspx. A remote attacker could exploit this vulnerability by sending a HTTP request with a malicious SQL query to the target server. Successful exploitation could allow the attacker to access and modify potentially sensitive information.