Category Archives: Full Disclosure

Full Disclosure

Path traversal vulnerability in EMC M&R (Watch4net) Device Discovery

Posted by Securify B.V. on Mar 18

————————————————————————
Path traversal vulnerability in EMC M&R (Watch4net) Device Discovery
————————————————————————
Han Sahin, November 2014

————————————————————————
Abstract
————————————————————————
A path traversal vulnerability was found in EMC…

Path traversal vulnerability in EMC M&R (Watch4net) MIB Browser

Posted by Securify B.V. on Mar 18

————————————————————————
Path traversal vulnerability in EMC M&R (Watch4net) MIB Browser
————————————————————————
Han Sahin, November 2014

————————————————————————
Abstract
————————————————————————
A path traversal vulnerability was found in EMC M&R…

[CORE-2015-0006] – Fortinet Single Sign On Stack Overflow

Posted by CORE Advisories Team on Mar 18

1. Advisory Information

Title: Fortinet Single Sign On Stack Overflow
Advisory ID: CORE-2015-0006
Advisory URL: http://www.coresecurity.com/advisories/fortinet-single-sign-on-stack-overflow
Date published: 2015-03-18
Date of last update: 2015-03-18
Vendors contacted: Fortinet
Release mode: Coordinated release

2. Vulnerability Information

Class: Stack-based Buffer Overflow [CWE-121]
Impact: Code execution
Remotely Exploitable: Yes
Locally…

Error messages of Websense Content Gateway are vulnerable to Cross-Site Scripting

Posted by Securify B.V. on Mar 18

————————————————————————
Error messages of Websense Content Gateway are vulnerable to Cross-Site
Scripting
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
It was discovered that the error…

Multiple Cross-Site Scripting vulnerabilities in Websense Reporting

Posted by Securify B.V. on Mar 18

————————————————————————
Multiple Cross-Site Scripting vulnerabilities in Websense Reporting
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
It has been found that Websense Reporting is affected…

Cross-Site Scripting vulnerability in Websense Explorer report scheduler

Posted by Securify B.V. on Mar 18

————————————————————————
Cross-Site Scripting vulnerability in Websense Explorer report scheduler
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
It was discovered that the report scheduler of…

Cross-Site Scripting vulnerability in Websense Data Security block page

Posted by Securify B.V. on Mar 18

————————————————————————
Cross-Site Scripting vulnerability in Websense Data Security block page
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
It was discovered that the Websense Data Security…

Missing access control on Websense Explorer web folder

Posted by Securify B.V. on Mar 18

————————————————————————
Missing access control on Websense Explorer web folder
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
It was discovered that no access control is enforced on the…

Source code disclosure of Websense Triton JSP files via double quote character

Posted by Securify B.V. on Mar 18

————————————————————————
Source code disclosure of Websense Triton JSP files via double quote
character
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
Websense Triton is affected by a source…

Command injection vulnerability in network diagnostics tool of Websense Appliance Manager

Posted by Securify B.V. on Mar 18

————————————————————————
Command injection vulnerability in network diagnostics tool of Websense
Appliance Manager
————————————————————————
Han Sahin, September 2014

————————————————————————
Abstract
————————————————————————
A command injection…