Category Archives: Full Disclosure

Full Disclosure

PDFMate PDF Converter Pro 1.7.5.0 – Buffer Overflow Vulnerability

Posted by Vulnerability Lab on Feb 20

Document Title:
===============
PDFMate PDF Converter Pro 1.7.5.0 – Buffer Overflow Vulnerability

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2029

Release Date:
=============
2017-01-30

Vulnerability Laboratory ID (VL-ID):
====================================
2029

Common Vulnerability Scoring System:
====================================
5.9

Product & Service Introduction:…

Telekom Cloud SSO – Multiple Persistent XSS Vulnerabilities

Posted by Vulnerability Lab on Feb 20

Document Title:
===============
Telekom Cloud SSO – Multiple Persistent XSS Vulnerabilities

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2021

Incident ID: 20161205_FKr_02

Vulnerability Magazine:
https://www.vulnerability-db.com/?q=articles/2017/01/03/telekom-cloud-web-sso-vulnerable-bypass-persistent-xss-attacks

Security Acknowledgements:…

Lithium Forum – (Compose Message) SSRF Vulnerability

Posted by Vulnerability Lab on Feb 20

Document Title:
===============
Lithium Forum – (Compose Message) SSRF Vulnerability

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2030

Release Date:
=============
2017-02-20

Vulnerability Laboratory ID (VL-ID):
====================================
2030

Common Vulnerability Scoring System:
====================================
5.7

Product & Service Introduction:…

Elefant CMS 1.3.12-RC: Multiple Persistent and Reflected XSS

Posted by Curesec Research Team (CRT) on Feb 16

Security Advisory – Curesec Research Team

1. Introduction

Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability XSS
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…

"long" filenames mishandled by Fujitsu's ScanSnap software

Posted by Stefan Kanthak on Feb 16

Hi @ll,

Fujitsu’s ScanSnap software installers WinSSInstiX500WW1.exe
and WinSSInstS1100iWW1.exe, available from
<http://www.fujitsu.com/global/support/products/computing/peripheral/scanners/scansnap/software/ix500w-installer.html>
and
<http://www.fujitsu.com/global/support/products/computing/peripheral/scanners/scansnap/software/s1100i.html>,
execute C:Program.exe multiple times near the end of the
installation process….

Elefant CMS 1.3.12-RC: Code Execution

Posted by Curesec Research Team (CRT) on Feb 16

Security Advisory – Curesec Research Team

1. Introduction

Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability Code Execution
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…

Elefant CMS 1.3.12-RC: Code Execution

Posted by Curesec Research Team (CRT) on Feb 16

Security Advisory – Curesec Research Team

1. Introduction

Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability Code Execution
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…

Plone: XSS

Posted by Curesec Research Team (CRT) on Feb 16

Security Advisory – Curesec Research Team

1. Introduction

Affected Product: Plone 5.0.5
Fixed in: Hotfix 20170117
Fixed Version Link: https://plone.org/security/hotfix/20170117
Vendor Contact: security () plone org
Vulnerability Type: XSS
Remote Exploitable: Yes
Reported to vendor: 09/05/2016
Disclosed to public: 01/26/2017
Release mode: Coordinated Release
CVE: CVE-2016-7147
Credits…

QNAP QTS 4.2.x multiple vulnerabilities

Posted by Harry Sintonen on Feb 15

QNAP QTS 4.2.x multiple vulnerabilities
=======================================
The latest version of this advisory is available at:
https://sintonen.fi/advisories/qnap-qts-42-multiple-vulnerabilities.txt

Overview
——–

QNAP QTS firmware contain Missing Transport Layer Security (CWE-319),
Improper Certificate Validation (CWE-295), Command Injection (CWE-77),
Cross-Site Scripting (CWE-79) and Information Exposure (CWE-200)
vulnerabilities…