Category Archives: Full Disclosure

Full Disclosure

XSS vulnerability in manage engine.

Posted by Suraj Krishnaswami on Jun 23

Title:
===============
ManageEngine Asset Explorer v6.1 – XSS Vulnerability

CVE-ID:
====================================
CVE-2015-2169

CVSS:
====================================
3.5

Product & Service Introduction (Taken from their homepage):
====================================
ManageEngine AssetExplorer is a web-based IT Asset Management (ITAM)
software that helps you monitor and manage assets in your network from
Planning phase to…

Minds.com – Several Issues

Posted by Scott Arciszewski on Jun 23

The Hype
========

Before we begin, let’s look at some of the hype that the Minds.com
team has been feeding into on Twitter.

https://twitter.com/minds/status/611536729175130112 ~>

https://twitter.com/minds/status/612023517962477568 ~>

https://twitter.com/minds/status/610499794834821121 ~>

https://twitter.com/WiredUK/status/610732859373043712 ~>

Wow, if Anonymous backs this project, surely it must be legitimate and
secure,…

New version: smalisca – Static Code Analysis tool for Smali files

Posted by Levon Kayan on Jun 23

Hi,

We released a version 0.2 of smalisca.

[ DESCRIPTION ]

A static code analysis tool for Smali files.

If you ever have looked at Android applications you know to appreciate
the ability of analyzing your target at the most advanced level. Dynamic
programm analysis will give you a pretty good overview of your
applications activities and general behaviour. However sometimes you’ll
want to just analyze your
application without running it….

CVE-2015-4557 – WordPress “Nextend Twitte r Connect” & “Nextend Google Connect” Cross Sit e Scripting

Posted by Liran Segal on Jun 23

WordPress “Nextend Twitter Connect”
===================================
Document Title:
===============
WordPress “Nextend Twitter Connect” Plugin Version: 1.5.1 is vulnerable to Reflected XSS (Cross Site Scripting)

Download URL:

=============

https://wordpress.org/plugins/nextend-twitter-connect/

Release Date:

=============
2015-06-20

Vulnerability CVE ID:

=====================
CVE-2015-4557

Vulnerability Disclosure Timeline:…

CVE-2015-4413 – WordPress “Nextend Facebo ok Connect” Cross Site Scripting

Posted by Liran Segal on Jun 23

Document Title:
===============
WordPress “Nextend Facebook Connect” Plugin Version: 1.5.4 is vulnerable to Reflected XSS (Cross Site Scripting)

Download URL:

=============

https://wordpress.org/plugins/nextend-facebook-connect/

Release Date:

=============
2015-06-20

Vulnerability CVE ID:

=====================
CVE-2015-4413

Vulnerability Disclosure Timeline:

==================================
2015 – 06 – 03 First notified to…

ERPSCAN Research Advisory [ERPSCAN-15-009] SAP Afaria 7 XcListener – Missing authorization check

Posted by Darya Maenkova on Jun 23

ERPSCAN Research Advisory [ERPSCAN-15-009] SAP Afaria 7 XcListener –
Missing authorization check

Application: SAP Afaria 7
Versions Affected: SAP Afaria 7, probably others
Vendor URL: http://SAP.com
Bugs: Missing authorization check
Sent: 09.12.2014
Reported: 09.12.2014
Vendor response: 10.12.2014
Date of Public Advisory: 18.06.2015
Reference:…

ERPSCAN Research Advisory [ERPSCAN-15-008] SAP Afaria 7 XcListener – DoS in the module XeClient.Dll

Posted by Darya Maenkova on Jun 23

<https://www.linkedin.com/company/2217474?trk=ppro_cprof>ERPSCAN
Research Advisory [ERPSCAN-15-008] SAP Afaria 7 XcListener – DoS in the
module XeClient.Dll

Application: SAP Afaria 7
Versions Affected: SAP Afaria 7, probably others
Vendor URL: http://SAP.com
Bugs: DoS
Sent: 09.12.2014
Reported: 09.12.2014
Vendor response: 10.12.2014
Date of Public…

ERPSCAN Research Advisory [ERPSCAN-15-007] SAP Management Console ReadProfile Parameters – Information disclosure

Posted by Darya Maenkova on Jun 23

ERPSCAN Research Advisory [ERPSCAN-15-007] SAP Management Console
ReadProfile Parameters – Information disclosure

Application: SAP Management Console
Versions Affected: SAP NW 7.4 Management Console, probably others
Vendor URL: http://SAP.com
Bugs: Information disclosure
Sent: 09.12.2014
Reported: 09.12.2014
Vendor response: 10.12.2014
Date of Public Advisory:…

ERPSCAN Research Advisory [ERPSCAN-15-006] SAP NetWeaver Portal ReportXmlViewer – XXE

Posted by Darya Maenkova on Jun 23

ERPSCAN Research Advisory [ERPSCAN-15-006] SAP NetWeaver Portal
ReportXmlViewer – XXE

Application: SAP NetWeaver Portal 7.31
Versions Affected: SAP NetWeaver Portal 7.31, probably others
Vendor URL: http://SAP.com
Bugs: XXE
Sent: 09.12.2014
Reported: 09.12.2014
Vendor response: 10.12.2014
Date of Public Advisory: 18.06.2015
Reference: SAP…