New User, Welcome!     Login

Next Page >>

Procheckup Ltd

PR09-17: Juniper Secure Access seriers (Juniper IVE) authenticated XSS & REDIRECTION

References:
http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2010-05-751&viewMode=view


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-04

Advisory publicly released: Tuesday, 21 December 2010
Vulnerability found: Thursday, 4 February 2010
Vendor informed: Monday, 8 February 2010
Severity level: Low/Medium
Credits
Richard Brain of ProCheckUp Ltd (www.procheckup.com)
Description
Viva Thumbs resizes and display images, as part of a popular WordPress
plugin.ProCheckUp has discovered that Viva Thumbs is vulnerable to a
directory traversal attack within the image display functionality, the
directory traversal attack is limited to file existence validation.

PR08-15: Several Webroot Disclosures on Moodle

References:

http://moodle.org/mod/forum/discuss.php?d=101403
http://www.procheckup.com/Vulnerabilities.php

Credits: Richard Brain of ProCheckUp Ltd. (www.procheckup.com)

ProCheckUp would like to thank Petr Skoda and the rest of the Moodle
team for their excellent response time and cooperation towards resolving
this matter.


PR08-23: XSS on Novell GroupWise WebAccess

Advisory publicly released:  30th January 2009

Severity: Medium

Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com).
ProCheckUp thanks Novell for working with us in such a professional manner.

Successfully tested on: Novell GroupWise WebAccess 7.0.3

Novell has confirmed the following versions to be affected by this

PR08-09: Unauthenticated File Retrieval on Sun Java System Identity Manager "ext" parameter

Date Public: 10th November 2008

Severity: High

Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com).

ProCheckUp thanks Sun for working with us.

Description:


PR07-43: Cross-domain redirect on RSA Authentication Agent

http://www.procheckup.com/Vulnerabilities.php
http://www.rsa.com/node.aspx?id=2807


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com).
ProCheckUp thanks RSA for being so cooperative and responding so fast.


Legal:


PR07-42: Webroot disclosure on Juniper Networks Secure Access 2000

http://www.procheckup.com/Vulnerabilities.php
http://www.juniper.net/products_and_services/ssl_vpn_secure_access/secure_access_2000/


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


COMPLETE HTTP REQUEST:

GET /dana-na/auth/remediate.cgi?step=preauth HTTP/1.1

PR07-41: XSS on Juniper Networks Secure Access 2000

http://www.procheckup.com/Vulnerabilities.php
http://www.juniper.net/products_and_services/ssl_vpn_secure_access/secure_access_2000/


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


COMPLETE HTTP REQUEST:

GET 

PR08-13: Persistent Cross-site Scripting (XSS) on Moodle via blog entry title

References:

http://moodle.org/mod/forum/discuss.php?d=101401
http://www.procheckup.com/Vulnerabilities.php

Credits: Adrian Pastor and Amir Azam of ProCheckUp Ltd. (www.procheckup.com)

ProCheckUp would like to thank Petr Skoda and the rest of the Moodle
team for their excellent response time and cooperation towards resolving
this matter.


PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profile page

References:

http://moodle.org/mod/forum/discuss.php?d=101405
http://www.procheckup.com/Vulnerabilities.php

Credits: Amir Azam and Adrian Pastor of ProCheckUp Ltd. (www.procheckup.com)

ProCheckUp would like to thank Petr Skoda and the rest of the Moodle
team for their excellent response time and cooperation towards resolving
this matter.


PR07-43: Cross-domain redirect on RSA Authentication Agent

http://www.procheckup.com/Vulnerabilities.php
http://www.rsa.com/node.aspx?id=2807


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com).
ProCheckUp thanks RSA for being so cooperative and responding so fast.


Legal:


PR07-44: XSS on RSA Authentication Agent login page

http://www.procheckup.com/Vulnerability_2007.php
http://www.rsa.com/node.aspx?id=2807


Credits: found by Jan Fry and Adrian Pastor - ProCheckUp Ltd
(www.procheckup.com). ProCheckUp thanks RSA for being so cooperative and
responding so fast.

COMPLETE HTTP REQUEST for simple XSS PoC:


PR08-22: Persistent XSS on Novell GroupWise WebAccess

Advisory publicly released:  30th January 2009

Severity: High

Credits: Jan Fry of ProCheckUp Ltd (www.procheckup.com). ProCheckUp
thanks Novell for working with us in such a professional manner.

Successfully tested on: Novell GroupWise WebAcess 7.0.3

Novell has confirmed the following versions to be affected by this

PR07-44: XSS on RSA Authentication Agent login page

http://www.procheckup.com/Vulnerability_2007.php
http://www.rsa.com/node.aspx?id=2807


Credits: found by Jan Fry and Adrian Pastor - ProCheckUp Ltd
(www.procheckup.com). ProCheckUp thanks RSA for being so cooperative and
responding so fast.

COMPLETE HTTP REQUEST for simple XSS PoC:


PR10-06: Cross-domain redirect on PGP Universal Web Messenger

Vulnerability found: Wednesday, 10 February 2010
Vendor informed: Wednesday, 10 February 2010
Vulnerability fixed: Tuesday, 14 December 2010
Severity level: Medium/High
Credits
Jan Fry of ProCheckUp Ltd (www.procheckup.com).
Description
A remote URI redirection vulnerability affects the PGP Universal Web
Messenger. This issue is due to a failure of the application to properly
sanitize URI-supplied data assigned to the 'retryURL' parameter.


PR10-13: Multiple XSS and Authentication flaws within BMC Remedy Knowledge Management

.

References:
http://www.procheckup.com/Vulnerabilities.php

Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)

Legal:
Copyright 2010 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the

PR09-16: Juniper Secure Access series (Juniper IVE) Cross-Site Scripting Vulnerability

Internet connected interface, by disabling WeBUI within service
options on the Internet connected interface.



Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

XSS with mod_perl perl_status utility

Advisory last updated: 1st March 2009 

Severity: Medium/High

Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)
 
CVE reference: CVE-2009-0796 
BID: 34383

Many thanks to Torsten Foertsch for his kind assistance in fixing the bug.

PR07-40: Authentication Bypass, Passwords Leakage and SNMP Injection on 3Com AP 8760

Date Public: 14th November 2008

Severity: Medium

Credits: Adrian Pastor of ProCheckUp Ltd (www.procheckup.com).

Vulnerability #1:

Description:


PR08-24: Proxim Tsunami MP.11 2411 vulnerable to SNMP Injection

Advisory publicly released: 9th October 2008

Severity: High

Credits: Adrian Pastor of ProCheckUp Ltd (www.procheckup.com)

Description:

Attackers can inject a malicious HTML/JavaScript payload via the
"system.sysName.0" SNMP OID. Such payload is returned on the web

PR07-23: Non-persistent Cross-site Scripting (XSS) on Absolute Poll Manager XE admin page

Microsoft IIS 5.0
Absolute Poll Manager XE - Version 4.1

Severity: Medium/High

Authors: Richard Brain and Adrian Pastor of ProCheckUp Ltd (http://www.procheckup.com/)

Vendor URL: http://www.xigla.com/

Product URL: http://www.xigla.com/absolutepm/


PR10-07: Unauthenticated File Retrieval (traversal) within ColdFusion administration console

http://www.procheckup.com/Vulnerabilities.php
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2861   CVE-2010-2861


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2010 Procheckup Ltd. All rights reserved.

PR09-15: XSS injection vulnerability within HP System Management Homepage (Insight Manager)

HP have issued a fix, download the appropiate update for your operating
system ensuring the sytem management agent is ay least version 6.0.0.96
or above.

Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2009 ProCheckUp Ltd. All rights reserved.

PR10-17 Various XSS and information disclosure flaws within KeyFax response management system

http://www.procheckup.com/Vulnerabilities.php



Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2010 ProCheckUp Ltd. All rights reserved.

PR07-31: Unauthenticated SQL Injection, XSS on Login Page and Username Enumeration on DPSnet Case Progress

ProCheckUp Security Vulnerabilities and Advisories:
http://www.procheckup.com/Vulnerabilities.php


Credits: Adrian Pastor of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Various Orion application application server example pages are vulnerable to XSS.

http://www.procheckup.com/Vulnerabilities.php



Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

PR10-14 Unauthenticated command execution within Mitel's AWC (Mitel Audio and Web Conferencing)

Advisory publicly released: Tuesday, 21 December 2010
Vulnerability found: Wednesday, 21 July 2010
Vendor informed: Monday, 26 July 2010
Severity level: High/Critical
Credits
Jan Fry of ProCheckUp Ltd (www.procheckup.com)
Description
Mitel Audio and Web Conferencing (AWC) is a simple, cost-effective and
scalable audio and web conferencing solution supporting upto 200 ports.
http://www.mitel.com/DocController?documentId=26451
ProCheckUp has discovered that the AWC web user interface is vulnerable

PR07-44: XSS on RSA Authentication Agent login page

http://www.procheckup.com/Vulnerability_2007.php
http://www.rsa.com/node.aspx?id=2807


Credits: found by Jan Fry and Adrian Pastor - ProCheckUp Ltd
(www.procheckup.com). ProCheckUp thanks RSA for being so cooperative and
responding so fast.

COMPLETE HTTP REQUEST for simple XSS PoC:


PR08-19: XSS on Cisco IOS HTTP Server

Advisory publicly released: 14th January 2009

Severity: Medium

Credits: Adrian Pastor of ProCheckUp Ltd (www.procheckup.com)

Description:

Cisco IOS HTTP server is vulnerable to XSS within invalid parameters
processed by the "/ping" server-side binary/script.

PR10-11: Multiple XSS injection vulnerabilities and a offsite redirection flaw within HP System Management Homepage (Insight Manager)

operating system ensuring the sytem management agent is at least version
v8.5.1.3712  or above.



Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)



Legal:


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!