Posted by Vulnerability Lab on Feb 20
Document Title:
===============
PDFMate PDF Converter Pro 1.7.5.0 – Buffer Overflow Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2029
Release Date:
=============
2017-01-30
Vulnerability Laboratory ID (VL-ID):
====================================
2029
Common Vulnerability Scoring System:
====================================
5.9
Product & Service Introduction:…
Posted by Vulnerability Lab on Feb 20
Document Title:
===============
Telekom Cloud SSO – Multiple Persistent XSS Vulnerabilities
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2021
Incident ID: 20161205_FKr_02
Vulnerability Magazine:
https://www.vulnerability-db.com/?q=articles/2017/01/03/telekom-cloud-web-sso-vulnerable-bypass-persistent-xss-attacks
Security Acknowledgements:…
Posted by Vulnerability Lab on Feb 20
Document Title:
===============
Lithium Forum – (Compose Message) SSRF Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2030
Release Date:
=============
2017-02-20
Vulnerability Laboratory ID (VL-ID):
====================================
2030
Common Vulnerability Scoring System:
====================================
5.7
Product & Service Introduction:…
Posted by Curesec Research Team (CRT) on Feb 16
Security Advisory – Curesec Research Team
1. Introduction
Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability CSRF
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…
Posted by Curesec Research Team (CRT) on Feb 16
Security Advisory – Curesec Research Team
1. Introduction
Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability XSS
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…
Posted by Stefan Kanthak on Feb 16
Hi @ll,
Fujitsu’s ScanSnap software installers WinSSInstiX500WW1.exe
and WinSSInstS1100iWW1.exe, available from
<http://www.fujitsu.com/global/support/products/computing/peripheral/scanners/scansnap/software/ix500w-installer.html>
and
<http://www.fujitsu.com/global/support/products/computing/peripheral/scanners/scansnap/software/s1100i.html>,
execute C:Program.exe multiple times near the end of the
installation process….
Posted by Curesec Research Team (CRT) on Feb 16
Security Advisory – Curesec Research Team
1. Introduction
Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability Code Execution
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…
Posted by Curesec Research Team (CRT) on Feb 16
Security Advisory – Curesec Research Team
1. Introduction
Affected Product: Elefant CMS 1.3.12-RC
Fixed in: 1.3.13
Fixed Version https://github.com/jbroadway/elefant/releases/tag/
Link: elefant_1_3_13_rc
Vendor Website: https://www.elefantcms.com/
Vulnerability Code Execution
Type:
Remote Yes
Exploitable:
Reported to 09/05/2016
vendor:
Disclosed to 02/02/2017
public:
Release mode:…
Posted by Curesec Research Team (CRT) on Feb 16
Security Advisory – Curesec Research Team
1. Introduction
Affected Product: Plone 5.0.5
Fixed in: Hotfix 20170117
Fixed Version Link: https://plone.org/security/hotfix/20170117
Vendor Contact: security () plone org
Vulnerability Type: XSS
Remote Exploitable: Yes
Reported to vendor: 09/05/2016
Disclosed to public: 01/26/2017
Release mode: Coordinated Release
CVE: CVE-2016-7147
Credits…
Posted by Harry Sintonen on Feb 15
QNAP QTS 4.2.x multiple vulnerabilities
=======================================
The latest version of this advisory is available at:
https://sintonen.fi/advisories/qnap-qts-42-multiple-vulnerabilities.txt
Overview
——–
QNAP QTS firmware contain Missing Transport Layer Security (CWE-319),
Improper Certificate Validation (CWE-295), Command Injection (CWE-77),
Cross-Site Scripting (CWE-79) and Information Exposure (CWE-200)
vulnerabilities…
Software and Security Information