New User, Welcome!     Login

Next Page >>

command injection

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices

each component of the solution is addressed independently in its own
advisory. This advisory addresses Cisco TelePresence endpoint devices
and details the following vulnerabilities:

  * Unauthenticated Common Gateway Interface (CGI) Access
  * CGI Command Injection
  * TFTP Information Disclosure
  * Malicious IP Address Injection
  * XML-Remote Procedure Call (RPC) Command Injection
  * Cisco Discovery Protocol Remote Code Execution


Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Recording Server

Recording Server. This security advisory outlines details of the
following vulnerabilities:

  * Unauthenticated Java Servlet Access

  * Common Gateway Interface (CGI) Command Injection

  * Unauthenticated Arbitrary File Upload

  * XML-Remote Procedure Call (RPC) Arbitrary File Overwrite


Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Manager

Multiple vulnerabilities exist in the Cisco TelePresence Manager.
This security advisory outlines the details of the following
vulnerabilities:

  * Simple Object Access Protocol (SOAP) Authentication Bypass
  * Java Remote Method Invocation (RMI) Command Injection
  * Cisco Discovery Protocol Remote Code Execution

Duplicate Issue Identification in Other Cisco TelePresence Advisories
+--------------------------------------------------------------------


RE: [CVE-2011-2569] Cisco Nexus OS (NX-OS) - Command "injection" / sanitization issues.

 Additional information below.  For current updates to Cisco PSIRT
response, please see the Intellishield response URL stated above. 

---------------------------------------------------------------------
NX-OS - "less" sub-command - Command injection / sanitization issues.
---------------------------------------------------------------------

Affected Products:
==================


Re: iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Server login.php Command Injection Vulnerability

First advisory, mail list post and original jibe suggesting common.php 
issue is CVE-2008-5449:

iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration 
Server login.php Command Injection Vulnerability
http://archives.neohapsis.com/archives/bugtraq/2009-01/0111.html
The vulnerability is in a function of common.php which is called from the 
login.php page.
The Common Vulnerabilities and Exposures (CVE) project has assigned the 
name CVE-2008-5449 to this issue.

CORE-2010-0104 - LANDesk OS command injection

Hash: SHA1
 
      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

                 LANDesk command injection


1. *Advisory Information*

Title: LANDesk command injection

[MORNINGSTAR-2009-02] Multiple security issues in Cute News and UTF-8 Cute News

8.12.3 Non-Vulnerable packages

UTF-8b


8.13 PHP Code Injection for categories module
------------------------------------------------------------------------------------------------------------------------
Severity:     Medium
Requires:     Administrator level account

8.13.1 Proof of concept exploit

Multiple vulnerabilities in several IP camera products

Release date:   08/06/2011
Last update:    08/06/2011
Credits:        Roberto Paleari, Emaze Networks S.p.A (roberto.paleari@emaze.net)

[VULNERABILITY INFORMATION]
Class:         Hidden functionalities, command-injection, weak encryption

[AFFECTED PRODUCTS]
The vulnerabilities described in this advisory are related to a firmware shared
among several devices of different vendors. Unfortunately, we have not been
able to identify the actual firmware manufacturer: we asked the name of the

Pandora FMS Authentication Bypass and Multiple Input Validation Vulnerabilities

Vulnerabilities

CVE IDs in this security advisory:

1) Authentication bypass - CVE-2010-4279
2) OS Command Injection - CVE-2010-4278
3) SQL Injection - CVE-2010-4280
4) Blind SQL Injection - CVE-2010-4280
5) Path Traversal - CVE-2010-4281 - CVE-2010-4282 - CVE-2010-4283



eFront <= 3.6.10 (build 11944) Multiple Security Vulnerabilities

   Host: localhost
   Cookie: cookie_login[login]=admin;cookie_login[active]=1;cookie_login[user_type]=administrator;cookie_login[password]=1;cookie_password=1
   Connection: keep-alive
   
  +--------------------+
  | PHP Code Injection |
  +--------------------+
  
  The vulnerable code is located in /www/student.php
  
  123.       if (isset($_GET['course']) || isset($_GET['from_course'])) {

Cisco Security Advisory: Cisco Small Business SRP500 Series Command Injection Vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Cisco Security Advisory: Cisco Small Business SRP500 Series Command
Injection Vulnerability

Advisory ID: cisco-sa-20111102-srp500

Revision 1.0


Cisco Security Advisory: Cisco Small Business SRP 500 Series Multiple Vulnerabilities

=======

Cisco Small Business (SRP 500) Series Services Ready Platforms
contain the following three vulnerabilities:

  * Cisco SRP 500 Series Web Interface Command Injection
    Vulnerability
  * Cisco SRP 500 Series Unauthenticated Configuration Upload
    Vulnerability
  * Cisco SRP 500 Series Directory Traversal Vulnerability


ZoneMinder Multiple Vulnerabilities

Description (from the vendor site):
ZoneMinder is an integrated set of applications which provide a complete surveillance solution allowing capture, analysis, recording and monitoring of any CCTV or security cameras attached to a Linux based machine.


Overview:
ZoneMinder is prone to Command Injection, SQL Injcetion and XSS. All attacks are possible because of lack of user input sanitizing.

I. Command Injection
In the "zm_html_view_events.php" function executeFilter() doesn't validate user input.
In the "zm_html_view_state.php" parameter "run_state" is not validated.


[TSI-ADV-1202] Polycom Web Management Interface O.S. Command Injection

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====[ Tempest Security Intelligence - Advisory #02 / 2012 ]============
 
     Polycom Web Management Interface O.S. Command Injection
     -------------------------------------------------------

Authors:
    - Joao Paulo Caldas Campello:
        - @jpcampello

LifeSize Room Vulnerabilities

Vulnerability Summaries:
------------------------
Login page can be bypassed, granting administrative access to the web interface.
Unauthenticated OS command injection is possible through the web interface.
The easiest way to perform these attacks is using a web proxy.


Vulnerable Versions:
--------------------

CORE-2009-0521 - DX Studio Player Firefox plug-in command injection

Hash: SHA1

      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

    DX Studio Player Firefox plug-in command injection



1. *Advisory Information*


CORE-2010-1018 - Landesk OS command injection

      Core Security Technologies - CoreLabs Advisory
                 http://corelabs.coresecurity.com/

                 Landesk OS command injection


1. *Advisory Information*

Title: Landesk OS command injection
Advisory Id: CORE-2010-1018

Security Advisory: Banks in Australia

I. VULNERABILITY
-------------------------
XSS
Command Injection

Banks below are vulnerable:
BankSA. www.banksa.com.au
Commonwealth Bank. www.commbank.com.au
etc...

SA00001-2010

for small and medium sized enterprises looking for an inexpensive way to
effectively manage and develop their human resources."
Product link: http://www.orangehrm.com/

2. Vulnerability Information
Class: Cross site scripting, SQL injection, PHP code injection, Cross-site
request forgery
Impact: Session hijacking, unauthorized data access, privilege escalation,
user-assisted arbitrary command execution
Rating: Less critical
Remotely Exploitable: Yes

CORE-2009-0401 - StoneTrip S3DPlayers remote command injection

      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

       StoneTrip S3DPlayers remote command injection


1. *Advisory Information*

Title: StoneTrip S3DPlayers remote command injection

Cisco Security Advisory: Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities

    --> Backup, it is possible for a remote unauthenticated user to
    access the backup configuration file. This file contains all
    configuration parameters of the device, including the HTTP
    authentication password and VPN pre-shared-keys (PSKs).

  * Root operating system arbitrary command injection by an
    authenticated attacker
    A user who is authenticated to the device can inject arbitrary
    commands into the underlying operating system with root
    privileges, via the ping test and traceroute test parameters.


Aruba Networks multiple advisories: OS command injection in RAP web interface and 802.1X EAP-TLS user authentication bypass

Advisory # 1:

TITLE

OS Command Injection Vulnerability in Aruba Remote Access Point
Diagnostic Web Interface.

SUMMARY

An OS command injection vulnerability has been discovered in the Aruba

JibberBook GuestBook 2.3 Multiple Vulnerabilities

                </message>

###########################################################################
###########################################################################

=== [ HTML Code Injection ] ===

        [»] add new message
        
                <img src="">


Re: ZDI-10-121: Command Injection Remote Code Execution Vulnerability

Is the affected product Secure Backup accidentally missing from the subject line and the advisory title,
i.e. the correct title is Oracle Secure Backup Administration selector Command Injection Remote Code Execution Vulnerability?

Juha-Matti

ZDI Disclosures [zdi-disclosures@tippingpoint.com] wrote: 
> ZDI-10-121: Command Injection Remote Code Execution Vulnerability
> http://www.zerodayinitiative.com/advisories/ZDI-10-121
> July 13, 2010
> 

Cisco Security Response: Multiple Vulnerabilities in Cisco Unified Videoconferencing Products

UVC products.

This vulnerability is documented in Cisco bug ID CSCti54008 and has been
assigned CVE ID CVE-2010-3038.

Remote Command Injection on the Web Interface in Cisco UVC Products
+------------------------------------------------------------------

Several fields in the web server interface of Cisco UVC products are
vulnerable to a shell command injection vulnerability. An
administrator user who is authenticated to the web interface of Cisco

[Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection

- - Affected Components:
        
        . SAP NetWeaver 2004 < SP21
        . SAP NetWeaver 2004s < SP13

- - Vulnerability Class: HTML Code Injection

- - Remotely Exploitable: Yes

- - Locally Exploitable: Yes


iDefense Security Advisory 01.10.11: HP Network Node Manager Command Injection Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Jan 10, 2011

I. BACKGROUND

HP Network Node Manager Command Injection Vulnerability HP Network Node
Manager (NNM) is an application suite that is used to map out and
manage network topography. NNM runs on a variety of platforms,
including Linux and multiple versions of Windows. For more information,
see the vendor's site found at the following link:
http://www.openview.hp.com/products/nnm/index.html

[CVE-2011-2569] Cisco Nexus OS (NX-OS) - Command "injection" / sanitization issues.

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Cisco Nexus OS (NX-OS) - Command "injection" / sanitization issues.
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Discovery by:
 1) Peter Adkins <adkins.peter@gmail.com>

Access:
 1) Local; authenticated access is required.


ViArt Shopping Cart v3.5 Multiple Remote Vulnerabilities

then save the shopping cart for the tables to be revealed by 
browsing to: http://www.victim.com/cart_save.php
===============================================================

===============================================================
!risk 3 - Arbitrary Code Injection
High
Attackers can use this vulnerability to execute arbitrary code
on a legitimate user.
===============================================================


CORE-2009-0108: Multiple vulnerabilities in Sun Calendar Express Web Server

9. *References*

[1] http://www.sun.com/software/products/calendar_srvr/
[2] HTML Code Injection and Cross-Site Scripting
http://www.technicalinfo.net/papers/CSS.html.
[3] The Cross-Site Scripting FAQ (XSS)
http://www.cgisecurity.com/articles/xss-faq.shtml
[4] How to prevent Cross-Site Scripting Security Issues
http://support.microsoft.com/default.aspx?scid=KB;en-us;q252985

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!