New User, Welcome!     Login

Next Page >>

Digital Security Research Group

[DSECRG-09-011] HP StorageWorks 1_8 G2 Tape Autoloader - privilege escalation DOS

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-011


Application:                    HP StorageWorks 1/8 G2 Tape Autoloader
Versions Affected:              firmware v 2.30 and earlier 
Vendor URL:                     http://hp.com/
Bug:                            Privilege escalation
Exploits:                       YES
Reported:                       30.09.2008

[DSECRG-09-030] PrecisionID Datamatrix ActiveX control - Arbitrary File overwriting

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-030
!!!             original advisory            !!!
http://dsecrg.com/pages/vul/DSECRG-09-030.html


Application:                    PrecisionID activeX controls 
Versions Affected:              
Vendor URL:                     http://PrecisionID.com
Bugs:                           Arbitrary File overwriting

[DSECRG-09-065] TVUPlayer PlayerOcx.ocx ActiveX - Insecure method

ActiveX component contains insecure method that can overwrite any  file in system

Digital Security Research Group [DSecRG] Advisory #DSECRG-09-065


Application:             TVUPlayer 
Versions Affected:       Tested on v2.4.9beta1[build1797]
Vendor URL:              www.tvunetworks.com
Bugs:                    insecure method, File overwriting
Exploits:                YES

[DSECRG-09-015] SAP GUI 6.4 Buffer Overflow vulnerability

Digital Security Research Group [DSecRG] Advisory      #DSECRG-09-015

Original Advisory:   http://dsecrg.com/pages/vul/show.php?id=115


Application:                    SAP GUI for Windows,  EnjoySAP
Versions Affected:              Version 6.4 
Vendor URL:                     http://SAP.com
Bugs:                           Buffer Overflow
Exploits:                       YES

[DSECRG-09-040] SAP Netweaver wsnavigator XSS Security Vulnerability

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-040


Application:                    SAP Netweaver           
Versions Affected:              Version 6.4 - 7.0 
Vendor URL:                     http://SAP.com
Bugs:                           XSS
Exploits:                       YES
Reported:                       26.05.2009

[DSECRG-08-011] Astrosoft HelpDesk Multiple XSS

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-011


Application:                    Astrosoft HelpDesk
Versions Affected:              
Vendor URL:                     http://astrosoft.ru/
Bugs:                           Multiple XSS Injections
Exploits:                       YES

[DSECRG-09-068] SAP NetWaver SLD - multiple XSS

Digital Security Research Group [DSecRG] Advisory  DSecRG-09-068

Application:                    SAP NetWeaver SLD
Versions Affected:              6.4 - 7.02
Vendor URL:                     http://SAP.com
Bugs:                           XSS
Exploits:                       YES
Reported:                       14.12.2009
Vendor response:                15.12.2009

[DSECRG-09-037] abk-soft AbleSpace CMS 1.0 - Multiple security vulnerabilities

original advisory:  http://dsecrg.com/pages/vul/show.php?id=137




Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-037

Application:                    AbleSpace
Versions Affected:              1.0
Vendor URL:                     http://abk-soft.com/
Bugs:                           Multiple Blind SQL Injections, Multiple XSS

[DSECRG-09-035] Chance-i DiViS DVR ActiveX - Heap Overflow

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-035

original advisory:  http://dsecrg.com/pages/vul/DSECRG-09-035.html


Application:                Chance-i DiViS-Web DVR System ActiveX control
Versions Affected:          3,0,0,7
Vendor URL:                 http://www.chance-i.com/
Bug:                        Heap Overflow
Exploits:                   YES

Remote File Disclosure in phpCMS 1.2.2

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-005


Application:                    phpCMS
Versions Affected:              1.2.2
Vendor URL:                     http://www.phpcms.de
Bug:                            Remote File Disclosure, Get admin password
Exploits:                       YES

[DSECRG-08-015] Multiple Security Vulnerabilities in Dokeos 1.8.4

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-015


Application:                    Dokeos E-Learning System        
Versions Affected:              1.8.4
Vendor URL:                     http://dokeos.com
Bugs:                           Multiple SQL Injections,Multiple Blind SQL Injections,Multiple  XSS, etc.
Exploits:                       YES
Reported:                       25.01.2008

[DSECRG-09-064] SAP GUI - Insecure method, code execution

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-064

Application:                    SAP GUI 
Versions Affected:              SAP GUI (SAP GUI 7.1)    
Vendor URL:                     http://SAP.com
Bugs:                           Insecure method. Code Execution.
Exploits:                       YES
Reported:                       16.10.2009
Vendor response:                27.10.2009
Date of Public Advisory:        23.03.2010

[DSECRG-08-008] Textpattern 4.0.5 Multiple Security Vulnerabilities

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-008


Application:                    Txp CMS
Versions Affected:              4.0.5
Vendor URL:                     http://www.textpattern.com
Bugs:                           DOS, multiple XSS, etc.
Exploits:                       YES
Reported:                       11.01.2008

[DSECRG-09-020] Apache Geronimo - XSRF vulnerabilities

Original Advisory:  http://dsecrg.com/pages/vul/show.php?id=120


Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-020

Application:                Apache Geronimo Application Server
Versions Affected:          2.1 - 2.1.3
Vendor URL:                 http://geronimo.apache.org/
Bug:                        Multiple XSRF Vulnerabilities
Exploits:                   YES

[DSECRG-08-026] LFI in Open Azimyt CMS 0.22

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-026


Application:                    Open Azimyt CMS
Versions Affected:              0.22 minimal, 0.21 stable
Vendor URL:                     http://azimyt.net/
Bug:                            Local File Include
Exploits:                       YES
Reported:                       07.06.2008

[DSECRG-09-048] HP LaserJet printers - Multiple Stored XSS vulnerabilities

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-048

http://dsecrg.ru/pages/vul/show.php?id=148

Application:                HP LaserJet printer web interface
Vulnerable:                 HP LaserJet 2200, 4350, 4600, 5500, and many others
Vendor URL:                 http://www.hp.com/
Bug:                        Multiple Stored XSS Vulnerabilities
Exploits:                   YES
Reported:                   07.04.2009

[DSECRG-08-009] xoops 2.0.18 Local File Include

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-009


Application:                    XOOPS
Versions Affected:              XOOPS 2.0.18
Vendor URL:                     http://www.xoops.org/
Bugs:                           Local File Include,URL Redirecting  phishing
Exploits:                       YES
Reported:                       28.01.2008
Vendor response:                28.01.2008

[DSECRG-08-007] OpenBSD BGPD daemon Web Interface XSS.

[#DSECRG-08-007] Digital Security Research Group [DSecRG] Advisory


Application:                    OpenBSD BGPD daemon
Versions Affected:              OpenBSD 4.1 
Vendor URL:                     http://openbsd.org
Bugs:                           XSS
Exploits:                       YES

[DSECRG-08-018] Ruby 1.8.6 (Webrick Httpd 1.3.1) Directory traversal file Download Vulnerability

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-018


Application:                    Ruby 1.8.6 (WEBrick Web server Toolkit and applications that used  WEBrick, like Metasploit 3.1)
Versions Affected:              Ruby
                                1.8.4 and all prior versions 
                                1.8.5-p114 and all prior versions 
                                1.8.6-p113 and all prior versions  

[DSecRG-09-053] VMware Remoute Console - format string

Digital Security Research Group [DSecRG] Advisory       DSECRG-09-053


Application:                    VMware Remoute Console
Version:                        e.x.p build-158248
Vendor URL:                     http://vmware.com
Bugs:                           Format String Vulnerabilitys
Exploits:                       YES (PoC)
Reported:                       07.08.2009

[DSECRG-09-036] Chance-i Techno Vision Security System - Directory Traversal File Download

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-036

original advisory:  http://dsecrg.com/pages/vul/DSECRG-09-036.html
  
Application:                Chance-i DiViS DVR System web-server
Versions Affected:          2.0
Vendor URL:                 http://www.chance-i.com/
Bug:                        Directory Traversal File Download
Exploits:                   YES
Reported:                   13.03.2009

[DSECRG-08-017] Flyspray 0.9.9.4 Multiple Security Vulnerabilities

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-017


Application:                    Flyspray (web-based bug tracking system)
Versions Affected:              0.9.9.4
Vendor URL:                     http://www.flyspray.org
Bugs:                           SiXSS, Stored XSS, Brute Force
Exploits:                       YES
Reported:                       08.02.2008

[DSECRG-08-016] Jinzora 2.7.5 Multiple XSS

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-016


Application:                    Jinzora Media Jukebox
Versions Affected:              2.7.5
Vendor URL:                     http://www.jinzora.com/
Bugs:                           Multiple XSS Injections
Exploits:                       YES

[DSECRG-09-008] JOnAS(4.10.3) - Linked XSS Vulnerability

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-008
------------------link to original advisory --------------------------
http://www.dsecrg.com/pages/vul/show.php?id=81




Application:                    JOnAS (Java Open Application Server)
Versions Affected:              JOnAS(4.10.3) / Apache Tomcat (5.5.26) 

[DSECRG-08-010] VHD Web Pack 2.0 Local File Include

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-010


Application:                    VHD Web Pack 2.0
Versions Affected:              VHD Web Pack 2.0
Vendor URL:                     http://www.divideconcept.net/index.php?page=vhdwebpack/index.php

[DSECRG-08-029] Local File Include in Dokeos E-Learning System 1.8.5

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-029


Application:                    Dokeos E-Learning System        
Versions Affected:              1.8.5
Vendor URL:                     http://dokeos.com/
Bug:                            Local File Include
Exploits:                       YES
Reported:                       01.07.2008

[DSECRG-09-019] Apache Geronimo - XSS vulnerabilities.txt

Original advisory http://dsecrg.com/pages/vul/show.php?id=119


Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-019

Application:                Apache Geronimo Application Server
Versions Affected:          2.1 - 2.1.3
Vendor URL:                 http://geronimo.apache.org/
Bug:                        Multiple XSS Vulnerabilities

[DSECRG-09-039] Symantec Antivirus 10.0 ActiveX - buffer Overflow.

Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-039

Application:                    Symantec Antivirus Client Proxy         
Versions Affected:              Version 10
Vendor URL:                     http://symantec.com
Bugs:                           Buffer Overflow
Exploits:                       POC
Reported:                       04.05.2009
Vendor response:                07.05.2009
Date of Public Advisory:        17.02.2010

[DSECRG-09-018] Apache Geronimo - Directory Traversal vulnerabilities

Original Advisory: http://dsecrg.com/pages/vul/show.php?id=118


Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-018

Application:                Apache Geronimo Application Server
Versions Affected:          2.1 - 2.1.3
Vendor URL:                 http://geronimo.apache.org/
Bug:                        Directory Traversal File Upload

[DSECRG-08-020] Alcatel OmniPCX Office Remote Comand Execution

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-020


Application:                    Alcatel OmniPCX Office 
Versions Affected:              Alcatel OmniPCX Office since release 210/061.1 
Vendor URL:                     http://alcatel.com
Bugs:                           Remote command execution
Exploits:                       YES
Risk:                           High

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!