Category Archives: Full Disclosure

Full Disclosure

K2 (Joomla! Extension) < 2.7.1 – Reflected Cross Site Scripting

Posted by Manuel Mancera on Aug 05

================================================================
K2 Joomla! Extension < 2.7.1 – Reflected Cross Site Scripting
================================================================

Information
——————–
Name: K2 Joomla! Extension – Reflected Cross Site Scripting
Affected Software : K2
Affected Versions: < 2.7.1
Vendor Homepage : https://getk2.org/
http://extensions.joomla.org/extension/k2
Vulnerability Type :…

CVE-2016-6527 Possible Privilege Escalation in telecom of Samsung Mobile Phone

Posted by 0xr0ot on Aug 05

Hi,

Description of the potential vulnerability:
Severity: Medium
Affected versions: L(5.0/5.1), M(6.0)
Reported on: May 11, 2016
Disclosure status: Privately disclosed.
The vulnerability in SmartCall Activity components of Telecom application
can make crash and reboot a device when the malformed serializable object
is passed.

Fix:
http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016
SVE-2016-6244: Possible Privilege Escalation in…

CVE-2016-6526 Possible Privilege Escalation in telecom of Samsung Mobile Phone

Posted by 0xr0ot on Aug 05

Description of the potential vulnerability:
Severity: Medium
Affected versions: L(5.0/5.1), M(6.0)
Reported on: May 11, 2016
Disclosure status: Privately disclosed.
A vulnerability in SpamCall Activity components of Telecom application can
make crash and reboot a device when the malformed serializable object is
passed.

Fix:
http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016
SVE-2016-6242: Possible Privilege Escalation in telecom…

[SYSS-2016-063] VMware ESXi 6 – Improper Input Validation (CWE-20)

Posted by Matthias Deeg on Aug 05

Advisory ID: SYSS-2016-063
Product: VMware vSphere Hypervisor (ESXi)
Manufacturer: VMware, Inc.
Affected Version(s): VMware ESXi 6.0.0 build 3380124 (Update 1)
VMware vCenter Server 6.0 U2
Tested Version(s): VMware ESXi 6.0.0 build 3380124 (Update 1)
Vulnerability Type: Improper Input Validation (CWE-20)
Risk Level: Medium
Solution Status: Fixed
Manufacturer Notification: 2016-07-01
Solution Date: 2016-08-04
Public…

[SYSS-2016-065] NASdeluxe NDL-2400r: OS Command Injection

Posted by Klaus Eisentraut (SySS GmbH) on Aug 05

Advisory ID: SYSS-2016-065

Product: NASdeluxe NDL-2400r

Vendor: Starline Computer GmbH

Affected Version(s): 2.01.10

Tested Version(s): 2.01.09

Vulnerability Type: OS Command Injection (CWE-78)

Risk Level: High

Solution Status: no fix (product has reached EOL since 3 years)

Vendor Notification: 2016-07-04

Public Disclosure: 2016-08-03

CVE Reference: Not assigned

Author of Advisory: Klaus Eisentraut, SySS GmbH,…

D-Link NAS, DNS Series: Stored XSS via Unauthenticated SMB

Posted by Benjamin Daniel Mussler on Aug 05

D-Link NAS, DNS Series: Stored XSS via Unauthenticated SMB
<http://b.fl7.de/2016/08/d-link-nas-dns-xss-via-smb.html>

1. Affected Models/Versions
2. Summary
3. Technical Summary
4. Vulnerability Details
5. Exploitation / Proof of Concept
6. Timeline
7. See Also

########## 1. Affected Models/Versions ##########

The vulnerability was initially discovered on a **D-Link DNS-320 rev A**
device running **firmware version 2.05b8** (also known…

Ecwid Ecommerce Shopping Cart WordPress Plugin unauthenticated PHP Object injection vulnerability

Posted by Summer of Pwnage on Aug 05

————————————————————————
Ecwid Ecommerce Shopping Cart WordPress Plugin unauthenticated PHP
Object injection vulnerability
————————————————————————
Yorick Koster, June 2016

————————————————————————
Abstract
————————————————————————
A PHP Object injection…

Cross-Site Scripting in Store Locator Plus for WordPress

Posted by Summer of Pwnage on Aug 05

————————————————————————
Cross-Site Scripting in Store Locator Plus for WordPress
————————————————————————
Yorick Koster, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found in Store Locator…

DLL side loading vulnerability in VMware Host Guest Client Redirector

Posted by Securify B.V. on Aug 05

————————————————————————
DLL side loading vulnerability in VMware Host Guest Client Redirector
————————————————————————
Yorick Koster, December 2015

————————————————————————
Abstract
————————————————————————
A DLL side loading vulnerability was found in the…