CVE-2014-8493 – ZTE ZXHN H108L Authentication Bypass

Posted by Project Zero Labs on Nov 17

About the software
==================

ZTE ZXHN H108L is provided by some large Greek ISPs to their
subscribers.

Vulnerability Details
=====================

CWMP configuration is accessible only through the Administrator account.
CWMP is a protocol widely used by ISPs worldwide for remote provisioning
and troubleshooting their subscribers’ equipment. However editing the
CWMP configuration (more specifically sending the POST request)…

WebsiteBaker <=2.8.3 – Multiple Vulnerabilities

Posted by Manuel Garcia Cardenas on Nov 17

=============================================
MGC ALERT 2014-004
– Original release date: March 11, 2014
– Last revised: November 18, 2014
– Discovered by: Manuel Garcia Cardenas
– Severity: 10/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
————————-
Multiple Vulnerabilities in WebsiteBaker 2.8.3

II. BACKGROUND
————————-
WebsiteBaker helps you to create the website you want:…

Zoph <= 0.9.1 – Multiple Vulnerabilities

Posted by Manuel Garcia Cardenas on Nov 17

=============================================
MGC ALERT 2014-005
– Original release date: March 5, 2014
– Last revised: November 18, 2014
– Discovered by: Manuel Garcia Cardenas
– Severity: 10/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
————————-
Multiple Vulnerabilities in Zoph <= 0.9.1

II. BACKGROUND
————————-
Zoph (Zoph Organizes Photos) is a web based digital image…

ABRT for CentOS Linux is now live

ABRT is a collection of scripts that makes it easier to report bugs and
crashes in various components of the distribution to a central server.
Metadata from this allows developers and upstream projects to evaluate
their priority chain, and also get crucial information on why their
software might not be performing as expected on CentOS Linux.

This information is sent to the server in a json format text file, the
contents of which will never contain private date. The entire
specification for this report format is available at :
https://github.com/abrt/faf/wiki/uReport and I encourage everyone to
read it once, so as to build confidence in the process.

--------
You can enable ABRT reporting by running:
/usr/sbin/abrt-auto-reporting enabled

this script is provided by the 'abrt' rpm package.

--------
More details on ABRT on CentOS are available on the CentOS wiki at
http://wiki.centos.org/TipsAndTricks/ABRT ; The entire ABRT
documentation is available online at :
http://abrt.readthedocs.org/en/latest/ - this includes both user and
developer information.

For those looking to get started with hacking on ABRT, start by reading
through the advanced usage examples at :
http://abrt.readthedocs.org/en/latest/examples.html

--------
The reports posted by CentOS machines will currently land at the Fedora
Project hosted retrace server at : https://retrace.fedoraproject.org/

--------
For any problems or issues with the abrt code included in CentOS Linux,
or for any problems associated with abrt user experience on CentOS Linux
: please post reports at http://bugs.centos.org/ by selecting the right
Distribution version and component as 'abrt'.

All other conversations around abrt on CentOS Linux should goto the
CentOS-devel mailing list ( http://lists.centos.org/ ).

regards,