Category Archives: Full Disclosure

Full Disclosure

KL-001-2016-005 : Cisco Firepower Threat Management Console Hard-coded MySQL Credentials

Posted by KoreLogic Disclosures on Oct 05

KL-001-2016-005 : Cisco Firepower Threat Management Console Hard-coded MySQL
Credentials

Title: Cisco Firepower Threat Management Console Hard-coded MySQL Credentials
Advisory ID: KL-001-2016-005
Publication Date: 2016.10.05
Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2016-005.txt

1. Vulnerability Details

Affected Vendor: Cisco
Affected Product: Firepower Threat Management Console
Affected Version:…

KL-001-2016-004 : Cisco Firepower Threat Management Console Authenticated Denial of Service

Posted by KoreLogic Disclosures on Oct 05

KL-001-2016-004 : Cisco Firepower Threat Management Console Authenticated Denial
of Service

Title: Cisco Firepower Threat Management Console Authenticated Denial of Service
Advisory ID: KL-001-2016-004
Publication Date: 2016.10.05
Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2016-004.txt

1. Vulnerability Details

Affected Vendor: Cisco
Affected Product: Firepower Threat Management Console
Affected…

Flash Operator Panel 2.31.03 – CSV Persistent Vulnerability

Posted by Vulnerability Lab on Oct 05

Document Title:
===============
Flash Operator Panel 2.31.03 – CSV Persistent Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1908

Release Date:
=============
2016-10-05

Vulnerability Laboratory ID (VL-ID):
====================================
1908

Common Vulnerability Scoring System:
====================================
3.6

Product & Service Introduction:…

Cyberoam iview UTM v0.1.2.7 – (Ajax) XSS Web Vulnerability

Posted by Vulnerability Lab on Oct 05

Document Title:
===============
Cyberoam iview UTM v0.1.2.7 – (Ajax) XSS Web Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1850

Release Date:
=============
2016-10-04

Vulnerability Laboratory ID (VL-ID):
====================================
1850

Common Vulnerability Scoring System:
====================================
3.3

Product & Service Introduction:…

Clean Master v1.0 – Unquoted Path Privilege Escalation

Posted by Vulnerability Lab on Oct 05

Document Title:
===============
Clean Master v1.0 – Unquoted Path Privilege Escalation

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=1968

Release Date:
=============
2016-10-05

Vulnerability Laboratory ID (VL-ID):
====================================
1968

Common Vulnerability Scoring System:
====================================
4

Product & Service Introduction:…

Re: Critical Vulnerability in Ubiquiti UniFi

Posted by Gregory Sloop on Oct 04

I attempted private contact with Tim Pham and via email 12+ hours ago, but received no response since then.

I’ve spent some time trying to reproduce the reported vulnerability and have had no success. It certainly doesn’t help
that the steps to reproduce it are so poorly described or documented.
Without better documentation of the exploit, it seems impossible to determine if the report is just mis-informed,
blatantly false, or if…

Serimux SSH Console Switch v2.4 – Multiple Cross Site Vulnerabilities

Posted by Vulnerability Lab on Oct 04

Document Title:
===============
Serimux SSH Console Switch v2.4 – Multiple Cross Site Vulnerabilities

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=1942

Release Date:
=============
2016-10-04

Vulnerability Laboratory ID (VL-ID):
====================================
1942

Common Vulnerability Scoring System:
====================================
3.4

Product & Service Introduction:…

Sparkasse (Bank) – Service Security Advisory WB021 2016

Posted by Vulnerability Lab on Oct 04

Document Title:
===============
Sparkasse (Bank) – Service Security Advisory WB021 2016

References:
===========
https://www.vulnerability-lab.com/get_content.php?id=1959

Download (PDF): http://www.vulnerability-lab.com/resources/documents/spk-sec-WB021.pdf

Vulnerability Magazine:
https://vulnerability-db.com/?q=articles/2016/09/06/critical-vulnerabilities-sparkassen-bank-server-discovered-researchers-0

Release Date:
=============
2016-09-24…

FaceDancer 21 – New Universal Case for PenTests

Posted by Vulnerability Lab on Oct 04

Document Title:
===============
FaceDancer 21 – New Universal Case for PenTests

References:
===========
https://www.vulnerability-lab.com/get_content.php?id=1960

STL Files Download: https://www.vulnerability-lab.com/resources/documents/FaceDancer2-STL-Files.rar

Vulnerability Magazine:
https://vulnerability-db.com/?q=articles/2016/09/26/facedancer-2-platin-new-universal-case-pentests

Release Date:
=============
2016-09-26

Vulnerability…

AuraDVD Ripper Professional v1.6.3 – DLL Hijacking Exploit

Posted by Vulnerability Lab on Oct 04

Document Title:
===============
AuraDVD Ripper Professional v1.6.3 – DLL Hijacking Exploit

References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=1966

Release Date:
=============
2016-10-04

Vulnerability Laboratory ID (VL-ID):
====================================
1966

Common Vulnerability Scoring System:
====================================
4.3

Product & Service Introduction:…